MEDIUM

CVE-2023-6502

Gitlab GitLab 2024-05-23 CVSS v3.1
CVSS
6.5

Description

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

Summary dbcve.org

A denial of service vulnerability exists in GitLab CE/EE's wiki functionality. An attacker can trigger a DoS condition by submitting a specially crafted wiki page that causes excessive resource consumption or crashes the service.

Mitigation

Upgrade GitLab to version 16.10.6, 16.11.3, 17.0.1 or later to patch the vulnerability. If immediate patching is not possible, consider restricting wiki creation/editing permissions to trusted users until the upgrade can be performed.

Weakness (CWE)

CWE-1333

EPSS Score

0.51%
Probability of exploitation in next 30 days
42.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE