HIGH
CVE-2023-0518
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.
Summary dbcve.org
GitLab CE/EE contains a denial-of-service vulnerability in its Helm chart package registry functionality. Attackers can upload a specially crafted malicious Helm chart file that triggers excessive resource consumption or crashes the service, making it unavailable.
Mitigation
Upgrade GitLab to version 15.8.1 or later (or 15.6.7/15.7.6 for respective older branches). Until patched, restrict Helm chart upload permissions to trusted users only.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.22%
Probability of exploitation in next 30 days
67.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.