CVE-2023-1072

MEDIUM

GitLab 9.0-15.7.7, 15.8-15.8.3, 15.9-15.9.1 - Uncontrolled Resource Consumption via Commit Details Request

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

Scores

CVSS v3 4.3
EPSS 0.0036
EPSS Percentile 58.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (1)
gitlab/gitlab 9.0 - 15.7.8 (2 CPE variants)
Published Mar 09, 2023
Tracked Since Feb 18, 2026