PT-2025-1086 · Gitlab · Gitlab Ce/Ee

Xorzon

·

Published

2025-01-08

·

Updated

2025-08-05

·

CVE-2024-6324

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.7 through 17.5.5 GitLab CE/EE versions 17.6 through 17.6.3 GitLab CE/EE versions 17.7 through 17.7.1
Description An issue was discovered in GitLab CE/EE that allows a denial of service (DoS) by creating cyclic references between epics. The vulnerability is related to algorithmic complexity. Exploitation may allow a remote attacker to cause a denial of service.
Recommendations GitLab CE/EE versions prior to 17.5.5 are affected. GitLab CE/EE versions prior to 17.6.3 are affected. GitLab CE/EE versions prior to 17.7.1 are affected.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2025-00322
BIT-GITLAB-2024-6324
CVE-2024-6324

Affected Products

Gitlab Ce/Ee