Medium severity4.3NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-3904
CVE-2023-3904
Description
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <16.4.4
- (no CPE)range: <16.4.4, >=16.5 <16.5.4, >=16.6 <16.6.2
- Range: <16.4.4, >=16.5 <16.5.4, >=16.6 <16.6.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/418226nvdBroken Link
- hackerone.com/reports/2053154nvdPermissions Required
News mentions
1- GitLab Security Release: 16.6.2, 16.5.4, 16.4.4GitLab Security Releases · Dec 13, 2023