A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.
References
| Link | Resource |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/433147 | Broken Link |
| https://hackerone.com/reports/2261581 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
05 Aug 2025, 21:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitlab.com/gitlab-org/gitlab/-/issues/433147 - Broken Link | |
| References | () https://hackerone.com/reports/2261581 - Permissions Required | |
| CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
|
| First Time |
Gitlab gitlab
Gitlab |
|
| Summary |
|
05 Feb 2025, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-05 10:15
Updated : 2025-08-05 21:03
NVD link : CVE-2023-6386
Mitre link : CVE-2023-6386
CVE.ORG link : CVE-2023-6386
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
