Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43577
HistoryOct 08, 2023 - 4:43 a.m.

Denial Of Service (DoS)

2023-10-0804:43:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
gitlab
dos
autolinkfilter
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

gitlab is vulnerable to Denial of Service (DoS). A regular expression denial of service (ReDoS) vulnerability in the AutolinkFilter class allows a remote attacker to crash GitLab by sending a specially crafted Markdown payload to the preview_markdown endpoint.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%