CVE-2023-3364 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting GitLab CE/EE versions before 16.0.8, 16.1.3, and 16.2.2. This flaw allows an unauthenticated attacker to trigger a denial of service by sending specially crafted payloads to the preview_markdown endpoint, leveraging the AutolinkFilter. Rated with a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, requiring no user interaction or privileges, and can lead to a complete denial of service. While its EPSS score is low, indicating a low probability of exploitation, its FAUCET Risk Score is 64/100. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one article from GitLab Security confirming the patch release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.14, < 16.0.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 8.14, < 16.0.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.1, < 16.1.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.1, < 16.1.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.2, < 16.2.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.