A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/433147 | Broken Link |
https://hackerone.com/reports/2261581 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
05 Aug 2025, 21:03
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
|
First Time |
Gitlab gitlab
Gitlab |
|
Summary |
|
|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/433147 - Broken Link | |
References | () https://hackerone.com/reports/2261581 - Permissions Required |
05 Feb 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-05 10:15
Updated : 2025-08-05 21:03
NVD link : CVE-2023-6386
Mitre link : CVE-2023-6386
CVE.ORG link : CVE-2023-6386
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-770
Allocation of Resources Without Limits or Throttling