CVE-2023-6489 is a denial of service vulnerability affecting GitLab CE/EE versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4, and 16.10 prior to 16.10.2. An authenticated attacker can exploit this flaw via the chat integration feature to significantly increase GitLab instance resource usage, leading to service degradation. This vulnerability has a CVSS score of 6.5 (Medium), indicating a low attack complexity and the potential for high availability impact. There is currently no evidence of active exploitation, nor are there publicly available exploit modules like Metasploit or Nuclei. While there's limited community discussion, GitLab has released patches to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.10, < 16.10.2CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.7.7, < 16.8.6CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.9, < 16.9.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.7.7, < 16.8.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.7.7, < 16.8.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.