Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44823
HistoryDec 25, 2023 - 11:04 p.m.

Uncontrolled Resource Consumption

2023-12-2523:04:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
gitlab
vulnerability
resource consumption
project imports
denial of service

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

6.4

Confidence

High

EPSS

0

Percentile

13.3%

gitlab is vulnerable to Uncontrolled Resource Consumption. The vulnerability is due to When GitLab imports a project containing a Tar archive, and this archive includes a FIFO file, it causes the import process to get stuck. An attacker can exploit this by creating a Tar archive containing a FIFO file and importing it into GitLab potentially leads to Denial of Service.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

6.4

Confidence

High

EPSS

0

Percentile

13.3%