CVE-2024-7610Uncontrolled Resource Consumption in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 51.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab15.917.0.6+2
NVDgitlab/gitlab15.9.017.0.6+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-7610: A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 152024-08-08
GHSA
GHSA-f48g-wqmg-9r45: A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 152024-08-08

📋Vendor Advisories

2
GitLab
CVE-2024-7610: A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4,2024-08-08
Debian
CVE-2024-7610: gitlab - A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affectin...2024