PT-2024-38767 · Gitlab · Gitlab Ce/Ee+1

·

CVE-2024-8041

·

Published

2024-08-22

·

Updated

2024-09-11

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions prior to 17.1.6 GitLab CE/EE versions 17.2 prior to 17.2.4 GitLab CE/EE versions 17.3 prior to 17.3.1
Description: A Denial of Service (DoS) issue has been discovered in GitLab CE/EE. The issue could occur upon importing a maliciously crafted repository using the GitHub importer.
Recommendations: For GitLab CE/EE versions prior to 17.1.6, upgrade to version 17.1.6 or later. For GitLab CE/EE versions 17.2 prior to 17.2.4, upgrade to version 17.2.4 or later. For GitLab CE/EE versions 17.3 prior to 17.3.1, upgrade to version 17.3.1 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2024-8041
CVE-2024-8041

Affected Products

Gitlab
Gitlab Ce/Ee