MEDIUM
CVE-2023-6489
CVSS
6.5
Description
A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE's chat integration feature allows attackers to spike resource consumption, causing service degradation. The flaw affects versions 16.7.x before 16.8.6, 16.9.x before 16.9.4, and 16.10.x before 16.10.2.
Mitigation
Upgrade GitLab to version 16.8.6, 16.9.4, 16.10.2 or later. If immediate upgrade is not possible, consider temporarily disabling or rate-limiting the chat integration feature as a compensating control.
Weakness (CWE)
CWE-1333
EPSS Score
0.6%
Probability of exploitation in next 30 days
47.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.