Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-0886: 2023/CVE-2023-0886.json · master · GitLab.org / cves · GitLab

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVE
#js#git#auth

Skip to content

GitLab

Next

    • GitLab: the DevOps platform
    • Explore GitLab
    • Install GitLab
    • How GitLab compares
    • Get started
    • GitLab docs
    • GitLab Learn
  • Pricing

  • Talk to an expert

  • /

  • Help

    • Help

    • Support

    • Community forum

    • Submit feedback

    • Contribute to GitLab

    Projects Groups Snippets

  • Register

  • Sign in

  • GitLab.org

  • cves

  • Repository

Switch branch/tag

  • cves
  • 2023
  • CVE-2023-0886.json

Find file BlameHistoryPermalink

  • Publishing 0 updated advisories and 1 new advisories · b231d123

    🤖 GitLab Bot 🤖 authored Feb 22, 2023

    b231d123

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907