PT-2024-5507 · Gitlab+1 · Gitlab Ce/Ee+2

Published

2024-08-07

·

Updated

2024-08-29

·

CVE-2024-7610

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.9 through 17.0.5 GitLab CE/EE version 17.1 prior to 17.1.4 GitLab CE/EE version 17.2 prior to 17.2.2
Description A Denial of Service (DoS) condition has been discovered in GitLab CE/EE. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch, leading to uncontrolled resource consumption during search result processing. This can allow a remote attacker to cause a denial of service.
Recommendations For GitLab CE/EE versions 15.9 through 17.0.5, update to version 17.0.6 or later to resolve the issue. For GitLab CE/EE version 17.1 prior to 17.1.4, update to version 17.1.4 or later to resolve the issue. For GitLab CE/EE version 17.2 prior to 17.2.2, update to version 17.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to Elasticsearch results to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06156
BIT-GITLAB-2024-7610
CVE-2024-7610

Affected Products

Elasticsearch
Gitlab
Gitlab Ce/Ee