Medium severity4.3NVD Advisory· Published Apr 5, 2023· Updated Jun 17, 2026
CVE-2023-1787
CVE-2023-1787
Description
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.9.0,<15.9.4
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.9.0,<15.9.4
- cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*
- (no CPE)range: before 15.9.4, before 15.10.1
- (no CPE)range: >=15.9, <15.9.4
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1787.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/394817nvdBroken Link
News mentions
0No linked articles in our index yet.