CVE-2023-5825
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.
Summary dbcve.org
A vulnerability in GitLab CE/EE allows low-privileged users to cause memory exhaustion via CI/CD Components. By pointing a CI/CD Component to an incorrect path, an attacker triggers an infinite loop that consumes all server memory, resulting in Denial of Service.
Mitigation
Upgrade GitLab to version 16.3.6, 16.4.2, or 16.5.1 or later. As a temporary workaround, restrict or audit CI/CD Component usage until patching is possible.