Unrated severityNVD Advisory· Published Dec 15, 2023· Updated Nov 20, 2025
Improper Validation of Specified Type of Input in GitLab
CVE-2023-3904
Description
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.
Affected products
3- Range: <16.4.4, >=16.5 <16.5.4, >=16.6 <16.6.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/2053154mitretechnical-descriptionexploitpermissions-required
- gitlab.com/gitlab-org/gitlab/-/issues/418226mitreissue-tracking
News mentions
1- GitLab Security Release: 16.6.2, 16.5.4, 16.4.4GitLab Security Releases · Dec 13, 2023