Medium severity6.5NVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026
CVE-2023-0121
CVE-2023-0121
Description
A denial of service issue was discovered in GitLab CE/EE affecting all versions starting from 13.2.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2 which allows an attacker to cause high resource consumption using malicious test report artifacts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.2.4,<15.10.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.2.4,<15.10.8
- (no CPE)range: >=13.2.4, <15.10.8
- Range: starting from 13.2.4 before 15.10.8, starting from 15.11 before 15.11.7, starting from 16.0 before 16.0.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0121.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/387549nvdIssue TrackingVendor Advisory
- hackerone.com/reports/1774688nvdPermissions RequiredThird Party Advisory
News mentions
1- GitLab Security Release: 16.0.2, 15.11.7, and 15.10.8GitLab Security Releases · Jun 5, 2023