MEDIUM

CVE-2023-5825

Gitlab GitLab 2023-11-06 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

Summary dbcve.org

A vulnerability in GitLab CE/EE allows low-privileged users to cause memory exhaustion via CI/CD Components. By pointing a CI/CD Component to an incorrect path, an attacker triggers an infinite loop that consumes all server memory, resulting in Denial of Service.

Mitigation

Upgrade GitLab to version 16.3.6, 16.4.2, or 16.5.1 or later. As a temporary workaround, restrict or audit CI/CD Component usage until patching is possible.

Weakness (CWE)

CWE-835 Infinite Loop

EPSS Score

0.64%
Probability of exploitation in next 30 days
49.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE