PT-2024-7438 · Gitlab · Gitlab Ce/Ee

A92847865

·

Published

2024-10-09

·

Updated

2025-08-06

·

CVE-2024-9631

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 13.6 through 17.2.9 GitLab CE/EE versions 17.3 through 17.3.5 GitLab CE/EE versions 17.4 through 17.4.2
Description: An issue was discovered in GitLab CE/EE where viewing diffs of MR with conflicts can be slow. This issue is related to insufficient input validation, which may allow an attacker to cause a denial of service.
Recommendations: For GitLab CE/EE versions 13.6 through 17.2.9, consider optimizing the diff viewing process for MR with conflicts until a patch is available. For GitLab CE/EE versions 17.3 through 17.3.5, consider optimizing the diff viewing process for MR with conflicts until a patch is available. For GitLab CE/EE versions 17.4 through 17.4.2, consider optimizing the diff viewing process for MR with conflicts until a patch is available.

Exploit

Fix

Allocation of Resources Without Limits

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-08816
BIT-GITLAB-2024-9631
CVE-2024-9631

Affected Products

Gitlab Ce/Ee