PT-2024-9582 · Gitlab · Gitlab Ce/Ee
A92847865
·
Published
2024-12-11
·
Updated
2024-12-16
·
CVE-2024-8233
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 9.4 through 17.4.6
GitLab CE/EE versions 17.5 through 17.5.4
GitLab CE/EE versions 17.6 through 17.6.2
Description
The issue affects GitLab CE/EE and is related to an uncontrolled resource consumption. An attacker could cause a denial of service with requests for diff files on a commit or merge request. This could allow a remote attacker to cause a denial of service.
Recommendations
For versions 9.4 through 17.4.6, update to a version after 17.4.6 to resolve the issue.
For versions 17.5 through 17.5.4, update to a version after 17.5.4 to resolve the issue.
For versions 17.6 through 17.6.2, update to a version after 17.6.2 to resolve the issue.
As a temporary workaround, consider restricting access to diff files on commit or merge requests to minimize the risk of exploitation.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab Ce/Ee