HIGH
CVE-2023-4011
CVSS
7.5
Description
An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.
Summary dbcve.org
A denial of service vulnerability in GitLab EE versions 15.11 through 16.2.1 allows attackers to spike resource consumption, likely through a specific attack vector that exhausts memory, CPU, or other system resources, making the service unavailable.
Mitigation
Upgrade GitLab EE to version 16.2.2 or later to patch the resource consumption vulnerability.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.78%
Probability of exploitation in next 30 days
54.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.