PT-2024-9582 · Gitlab · Gitlab Ce/Ee

·

CVE-2024-8233

·

Published

2024-12-11

·

Updated

2024-12-16

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 9.4 through 17.4.6 GitLab CE/EE versions 17.5 through 17.5.4 GitLab CE/EE versions 17.6 through 17.6.2
Description The issue affects GitLab CE/EE and is related to an uncontrolled resource consumption. An attacker could cause a denial of service with requests for diff files on a commit or merge request. This could allow a remote attacker to cause a denial of service.
Recommendations For versions 9.4 through 17.4.6, update to a version after 17.4.6 to resolve the issue. For versions 17.5 through 17.5.4, update to a version after 17.5.4 to resolve the issue. For versions 17.6 through 17.6.2, update to a version after 17.6.2 to resolve the issue. As a temporary workaround, consider restricting access to diff files on commit or merge requests to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11289
BIT-GITLAB-2024-8233
CVE-2024-8233

Affected Products

Gitlab Ce/Ee