CVE-2023-6678
Publication date 12 April 2024
Last updated 13 December 2024
Ubuntu priority
Cvss 3 Severity Score
An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service using malicious crafted content in a junit test report file.
Status
Package | Ubuntu Release | Status |
---|---|---|
gitlab | ||
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
16.04 LTS xenial |
Not affected
|
Notes
alexmurray
Only affectes GitLab Enterprise Edition (EE) not Community Edition (CE) so gitlab in Ubuntu is not-affected.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |