HIGH

CVE-2023-0518

Gitlab GitLab 2023-02-13 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

Summary dbcve.org

GitLab CE/EE contains a denial-of-service vulnerability in its Helm chart package registry functionality. Attackers can upload a specially crafted malicious Helm chart file that triggers excessive resource consumption or crashes the service, making it unavailable.

Mitigation

Upgrade GitLab to version 15.8.1 or later (or 15.6.7/15.7.6 for respective older branches). Until patched, restrict Helm chart upload permissions to trusted users only.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.22%
Probability of exploitation in next 30 days
67.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE