Lucene search

K
nvd[email protected]NVD:CVE-2023-1733
HistoryApr 05, 2023 - 8:15 p.m.

CVE-2023-1733

2023-04-0520:15:07
web.nvd.nist.gov
denial of service
prometheus server
gitlab
versions 11.10 to 15.10.1

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

40.4%

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

Affected configurations

NVD
Node
gitlabgitlabRange11.10.015.8.5community
OR
gitlabgitlabRange11.10.015.8.5enterprise
OR
gitlabgitlabRange15.9.015.9.4community
OR
gitlabgitlabRange15.9.015.9.4enterprise
OR
gitlabgitlabMatch15.10.0community
OR
gitlabgitlabMatch15.10.0enterprise

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

40.4%