CVE-2023-4912: Client-side DOS via Mermaid Flowchart
An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-4912.
What is the severity of CVE-2023-4912?
The severity of CVE-2023-4912 is medium with a CVSS score of 6.5.
Which versions of GitLab are affected by CVE-2023-4912?
All versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, and version 16.6.0 of GitLab are affected by CVE-2023-4912.
What is the impact of this vulnerability?
This vulnerability allows an attacker to cause a client-side denial of service using malicious crafted mermaid diagrams.
How can I fix the vulnerability in GitLab?
Upgrade GitLab to version 16.4.3 or later, version 16.5.3 or later, or version 16.6.1 or later to fix the vulnerability.