PT-2025-5695 · Gitlab · Gitlab Ce/Ee

Joaxcar

·

Published

2025-02-05

·

Updated

2025-08-06

·

CVE-2024-2878

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.7 through 16.9.7 GitLab CE/EE versions 16.10 through 16.10.5 GitLab CE/EE versions 16.11 through 16.11.2
Description An issue has been discovered in GitLab CE/EE that could allow an attacker to cause a denial of service by crafting unusual search terms for branch names.
Recommendations For GitLab CE/EE versions 15.7 through 16.9.7, consider restricting access to branch name search functionality until a patch is available. For GitLab CE/EE versions 16.10 through 16.10.5, consider implementing input validation for branch name search terms to minimize the risk of exploitation. For GitLab CE/EE versions 16.11 through 16.11.2, consider disabling the branch name search feature temporarily until a fix is applied.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2024-2878
CVE-2024-2878

Affected Products

Gitlab Ce/Ee