cvelist/2023/3xxx/CVE-2023-3917.json

110 lines
3.7 KiB
JSON
Raw Normal View History

2023-07-25 11:00:33 +00:00
{
2023-09-29 07:00:35 +00:00
"data_version": "4.0",
2023-07-25 11:00:33 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2023-3917",
2023-09-29 07:00:35 +00:00
"ASSIGNER": "cve@gitlab.com",
"STATE": "PUBLIC"
2023-07-25 11:00:33 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2023-09-29 07:00:35 +00:00
"value": "Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-20: Improper Input Validation",
"cweId": "CWE-20"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "GitLab",
"product": {
"product_data": [
{
"product_name": "GitLab",
"version": {
"version_data": [
{
"version_affected": "<",
"version_name": "0",
"version_value": "16.2.8"
},
{
"version_affected": "<",
"version_name": "16.3",
"version_value": "16.3.5"
},
{
"version_affected": "<",
"version_name": "16.4",
"version_value": "16.4.1"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/417896",
"refsource": "MISC",
"name": "https://gitlab.com/gitlab-org/gitlab/-/issues/417896"
},
{
"url": "https://hackerone.com/reports/2055158",
"refsource": "MISC",
"name": "https://hackerone.com/reports/2055158"
}
]
},
"solution": [
{
"lang": "en",
"value": "Upgrade to version 16.4.1, 16.3.5 or 16.2.8"
}
],
"credits": [
{
"lang": "en",
"value": "Thanks [js_noob](https://hackerone.com/js_noob) for reporting this vulnerability through our HackerOne bug bounty program"
}
],
"impact": {
"cvss": [
{
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "LOW",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
2023-07-25 11:00:33 +00:00
}
]
}
}