HIGH
CVE-2023-1733
CVSS
7.5
Description
A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.
Summary dbcve.org
A denial of service vulnerability exists in the Prometheus server bundled with GitLab. The vulnerability affects specific versions of GitLab (11.10 to 15.8.5, 15.9 to 15.9.4, and 15.10 to 15.10.1) and can be exploited to cause a DoS condition in the Prometheus monitoring component.
Mitigation
Upgrade GitLab to version 15.8.6, 15.9.5, or 15.10.2 or later to receive the patched Prometheus server bundle.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.24%
Probability of exploitation in next 30 days
67.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.