CVE-2023-2132
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jun 6, 2023
Updated: Jan 7, 2025
CWE ID 1333
Summary
CVE-2023-2132 is a newly disclosed vulnerability affecting GitLab CE/EE versions 15.4 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2. This issue involves a DollarMathPostFilter Regular Expression Denial of Service (DoS) vulnerability found in the preview_markdown endpoint. Maliciously crafted payloads can be sent to exploit this flaw, causing denial-of-service conditions. GitLab users running susceptible versions are advised to update their software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.