HIGH

CVE-2023-4011

Gitlab GitLab 2023-08-02 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

Summary dbcve.org

A denial of service vulnerability in GitLab EE versions 15.11 through 16.2.1 allows attackers to spike resource consumption, likely through a specific attack vector that exhausts memory, CPU, or other system resources, making the service unavailable.

Mitigation

Upgrade GitLab EE to version 16.2.2 or later to patch the resource consumption vulnerability.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.78%
Probability of exploitation in next 30 days
54.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE