Medium severity4.3NVD Advisory· Published Apr 12, 2024· Updated Jun 17, 2026
CVE-2023-6489
CVE-2023-6489
Description
A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.7.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.7.7,<16.8.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.7.7,<16.8.6
- (no CPE)range: 16.7.7 < 16.8.6, 16.9 < 16.9.4, 16.10 < 16.10.2
- Range: 16.7.7 < 16.8.6, 16.9 < 16.9.4, 16.10 < 16.10.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/433520nvdBroken Link
- hackerone.com/reports/2262450nvdPermissions Required
News mentions
1- GitLab Patch Release: 16.10.2, 16.9.4, 16.8.6GitLab Security Releases · Apr 10, 2024