PT-2024-9582 · Gitlab · Gitlab Ce/Ee

A92847865

·

Published

2024-12-11

·

Updated

2024-12-16

·

CVE-2024-8233

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 9.4 through 17.4.6 GitLab CE/EE versions 17.5 through 17.5.4 GitLab CE/EE versions 17.6 through 17.6.2
Description The issue affects GitLab CE/EE and is related to an uncontrolled resource consumption. An attacker could cause a denial of service with requests for diff files on a commit or merge request. This could allow a remote attacker to cause a denial of service.
Recommendations For versions 9.4 through 17.4.6, update to a version after 17.4.6 to resolve the issue. For versions 17.5 through 17.5.4, update to a version after 17.5.4 to resolve the issue. For versions 17.6 through 17.6.2, update to a version after 17.6.2 to resolve the issue. As a temporary workaround, consider restricting access to diff files on commit or merge requests to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-11289
BIT-GITLAB-2024-8233
CVE-2024-8233

Affected Products

Gitlab Ce/Ee