Medium severity6.5NVD Advisory· Published Aug 2, 2023· Updated Jun 17, 2026
CVE-2023-0632
CVE-2023-0632
Description
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.
Affected products
5starting from 15.2 before 16.0.8, starting from 16.1 before 16.1.3, starting from 16.2 before 16.2.2+ 3 more
- (no CPE)range: starting from 15.2 before 16.0.8, starting from 16.1 before 16.1.3, starting from 16.2 before 16.2.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.2,<16.0.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.2,<16.0.8
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/390148nvdBroken Link
- hackerone.com/reports/1852677nvdPermissions Required
News mentions
1- GitLab Security Release: 16.2.2, 16.1.3, and 16.0.8GitLab Security Releases · Aug 1, 2023