CVE-2023-6489
MEDIUMGitLab CE/EE <16.8.6, <16.9.4, <16.10.2 - DoS
Title source: llmDescription
A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.
Scores
CVSS v3
4.3
EPSS
0.0002
EPSS Percentile
5.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-1333
Status
published
Affected Products (2)
gitlab/gitlab
< 16.8.6
gitlab/gitlab
< 16.8.6
Timeline
Published
Apr 12, 2024
Tracked Since
Feb 18, 2026