CVE-2023-5825: GitLab omnibus DoS crash via OOM with CI Catalogs
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this GitLab vulnerability?
The vulnerability ID for this GitLab vulnerability is CVE-2023-5825.
What is the severity of CVE-2023-5825?
CVE-2023-5825 has a severity of medium (6.5).
Which versions of GitLab are affected by this vulnerability?
This vulnerability affects all versions of GitLab starting from 16.2 before 16.3.6, starting from 16.4 before 16.4.2, and starting from 16.5 before 16.5.1.
How can a low-privileged attacker exploit CVE-2023-5825?
A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust resources.
Is there a fix available for CVE-2023-5825?
Yes, a fix is available for CVE-2023-5825. It is recommended to upgrade to GitLab versions 16.3.6, 16.4.2, or 16.5.1.