CVE-2024-5423
published 2024-08-08CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.46%
36.8th percentile
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 17.3.5-2 (sid) | gitlab 17.3.5-2 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | >= 1 < 17.0.6 | 17.0.6 |
| gitlab | gitlab | >= 1.0 < 17.0.6 | 17.0.6 |
| gitlab | gitlab | >= 17.1 < 17.1.4 | 17.1.4 |
| gitlab | gitlab | >= 17.1.0 < 17.1.4 | 17.1.4 |
| gitlab | gitlab | >= 17.2 < 17.2.2 | 17.2.2 |
| gitlab | gitlab | >= 17.2.0 < 17.2.2 | 17.2.2 |
| gitlab | gitlab_ce | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting fro
vendor_gitlab·2024-08-08·CVSS 6.5
CVE-2024-5423 [MEDIUM] CWE-400 CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting fro
CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.
Debian
CVE-2024-5423: gitlab - Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE ...
vendor_debian·2024·CVSS 6.5
CVE-2024-5423 [MEDIUM] CVE-2024-5423: gitlab - Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE ...
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.
Scope: local
sid: resolved (fixed in 17.3.5-2)
GHSA
GHSA-q28r-ggr6-763f: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1
ghsa_unreviewed·2024-08-08
CVE-2024-5423 [MEDIUM] CWE-400 GHSA-q28r-ggr6-763f: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.
OSV
CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1
osv·2024-08-08·CVSS 6.5
CVE-2024-5423 [MEDIUM] CVE-2024-5423: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-08
Published