Medium severity5.3NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026
CVE-2023-4647
CVE-2023-4647
Description
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.2.0,<16.1.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.2.0,<16.1.5
- cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*
- (no CPE)range: 15.2 <= v < 16.1.5, 16.2 <= v < 16.2.5, 16.3 <= v < 16.3.1
Patches
Vulnerability mechanics
References
1- gitlab.com/gitlab-org/gitlab/-/issues/414502nvdIssue TrackingVendor Advisory
News mentions
1- GitLab Security Release: 16.3.1, 16.2.5, and 16.1.5GitLab Security Releases · Aug 31, 2023