HIGH
CVE-2023-6386
CVSS
7.5
Description
A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE allows an attacker to spike instance resource usage by triggering excessive resource consumption, leading to service degradation. The vulnerability exists in versions 15.11 through 16.8.1 and stems from insufficient controls on resource-intensive operations.
Mitigation
Upgrade GitLab to version 16.6.7, 16.7.5, 16.8.2 or later to patch the vulnerability. During the upgrade, schedule a maintenance window and ensure backups are available.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.53%
Probability of exploitation in next 30 days
43.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.