CVE-2023-6489

CVSS V2 None CVSS V3 None
Description
A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.
Overview
  • CVE ID
  • CVE-2023-6489
  • Assigner
  • GitLab
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-12T00:53:41.230Z
  • Last Modified Date
  • 2024-04-12T04:04:38.091Z
References
Reference URL Reference Tags
https://gitlab.com/gitlab-org/gitlab/-/issues/433520 issue-tracking permissions-required
https://hackerone.com/reports/2262450 technical-description exploit
History
Created Old Value New Value Data Type Notes
2024-06-25 06:06:03 Added to TrackCVE