A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Thu, 03 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Allocation of Resources Without Limits or Throttling in GitLab | |
| Weaknesses | CWE-770 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-01-07T21:51:37.372Z
Reserved: 2023-02-20T00:00:00
Link: CVE-2023-0921
Updated: 2024-08-02T05:24:34.643Z
Status : Analyzed
Published: 2023-06-06T17:15:12.747
Modified: 2025-05-05T14:12:29.340
Link: CVE-2023-0921
No data.
OpenCVE Enrichment
No data.
Weaknesses