PT-2024-14946 · Gitlab · Gitlab Ce/Ee

Published

2024-02-07

·

Updated

2025-08-05

·

CVE-2023-6386

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.11 through 16.6.6 GitLab CE/EE versions 16.7 through 16.7.4 GitLab CE/EE versions 16.8 through 16.8.1
Description A denial of service issue was identified in GitLab CE/EE, which allows an attacker to increase the resource usage of the GitLab instance, resulting in service degradation.
Recommendations For GitLab CE/EE versions 15.11 through 16.6.6, update to version 16.6.7 or later. For GitLab CE/EE versions 16.7 through 16.7.4, update to version 16.7.5 or later. For GitLab CE/EE versions 16.8 through 16.8.1, update to version 16.8.2 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-05790
BIT-GITLAB-2023-6386
CVE-2023-6386

Affected Products

Gitlab Ce/Ee