CVE-2024-5423Uncontrolled Resource Consumption in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 36.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab117.0.6+2
NVDgitlab/gitlab1.017.0.6+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-q28r-ggr6-763f: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 12024-08-08
OSV
CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 12024-08-08

📋Vendor Advisories

2
GitLab
CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting fro2024-08-08
Debian
CVE-2024-5423: gitlab - Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE ...2024