CVE-2023-0921: Allocation of Resources Without Limits or Throttling in GitLab
A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0921?
CVE-2023-0921 is a moderate severity vulnerability due to its ability to impact CPU usage.
How do I fix CVE-2023-0921?
To fix CVE-2023-0921, upgrade GitLab to version 15.10.8 or later, 15.11.7 or later, or 16.0.2 or later.
Who is affected by CVE-2023-0921?
CVE-2023-0921 affects all versions of GitLab CE/EE from 8.3 to prior versions mentioned.
What type of attack is associated with CVE-2023-0921?
CVE-2023-0921 allows authenticated attackers to create large issue descriptions via GraphQL.
What are the potential impacts of CVE-2023-0921?
The potential impact of CVE-2023-0921 includes excessive CPU usage due to repeated requests for large issue descriptions.