HIGH

CVE-2023-3917

Gitlab GitLab 2023-09-29 CVSS v3.1
CVSS
7.5

Description

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

Summary dbcve.org

A denial-of-service vulnerability in GitLab CI/CD pipelines allows an attacker to cause pipeline executions to fail. The vulnerability affects GitLab Community Edition (CE) and Enterprise Edition (EE) across multiple version branches, potentially enabling unauthenticated or authenticated attackers to disrupt CI/CD workflows.

Mitigation

Upgrade GitLab to version 16.2.8, 16.3.5, or 16.4.1 or later to patch the pipeline DoS vulnerability.

Weakness (CWE)

CWE-1287

EPSS Score

0.78%
Probability of exploitation in next 30 days
54.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE