HIGH

CVE-2023-6386

Gitlab GitLab 2025-02-05 CVSS v3.1
CVSS
7.5

Description

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows an attacker to spike instance resource usage by triggering excessive resource consumption, leading to service degradation. The vulnerability exists in versions 15.11 through 16.8.1 and stems from insufficient controls on resource-intensive operations.

Mitigation

Upgrade GitLab to version 16.6.7, 16.7.5, 16.8.2 or later to patch the vulnerability. During the upgrade, schedule a maintenance window and ensure backups are available.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.53%
Probability of exploitation in next 30 days
43.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE