Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42173
HistoryAug 06, 2023 - 6:28 a.m.

Denial Of Service (DoS)

2023-08-0606:28:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2
gitlab
vulnerability
dos attacks
large number of requests
commit details
resources
memory
cpu
denial of service
software

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

33.8%

gitlab is vulnerable to Denial of Service (DoS) attacks. This vulnerability occurs when an attacker can send a large number of requests to read commit details. This could cause GitLab to run out of resources, such as memory or CPU, and could lead to a denial of service.

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

33.8%