Impact
GitLab’s CSV import processing lacks proper validation, allowing an authenticated user to craft an improper CSV file that, when ingested, can cause Sidekiq workers to terminate, leading to a denial of service that affects background job processing. This weakness falls under the allocation of resources without limits weakness.
Affected Systems
GitLab Community and Enterprise Editions, all releases from 11.7 up to 18.8.8, 18.9.0 to 18.9.4, and 18.10.0 to 18.10.2. The vulnerability has been fixed in GitLab 18.8.9, 18.9.5, and 18.10.3 and later releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Exploitation requires the attacker to be an authenticated user with permission to import CSV files, which is a common capability in many environments. The EPSS score is not available, so the current exploitation probability cannot be estimated, and the vulnerability is not listed in the CISA KEV catalog. The attack likely occurs locally or remotely from a user that has authenticated into GitLab’s web interface, using the CSV import interface to trigger the failure of Sidekiq workers.
OpenCVE Enrichment