Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3ph-4hj5-r598

Опубликовано: 27 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

EPSS

Процентиль: 39%
0.00171
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1333
CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

CVSS3: 6.5
nvd
больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

CVSS3: 6.5
debian
больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 39%
0.00171
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1333
CWE-400