MEDIUM

CVE-2023-6489

Gitlab GitLab 2024-04-12 CVSS v3.1
CVSS
6.5

Description

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE's chat integration feature allows attackers to spike resource consumption, causing service degradation. The flaw affects versions 16.7.x before 16.8.6, 16.9.x before 16.9.4, and 16.10.x before 16.10.2.

Mitigation

Upgrade GitLab to version 16.8.6, 16.9.4, 16.10.2 or later. If immediate upgrade is not possible, consider temporarily disabling or rate-limiting the chat integration feature as a compensating control.

Weakness (CWE)

CWE-1333

EPSS Score

0.6%
Probability of exploitation in next 30 days
47.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE