A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/392665 | broken link |
https://hackerone.com/reports/1723124 | permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1733.json | vendor advisory |