CVE-2024-8041Uncontrolled Resource Consumption in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22

Description

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab17.217.2.4+1
NVDgitlab/gitlab17.2.017.2.4+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-qvhh-qrj8-5g7c: A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 172024-08-22
OSV
CVE-2024-8041: A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 172024-08-22

📋Vendor Advisories

2
GitLab
CVE-2024-8041: A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 172024-08-22
Debian
CVE-2024-8041: gitlab - A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting al...2024