CVE-2024-9631Inefficient Algorithmic Complexity in Gitlab

Severity
7.5HIGHNVD
EPSS
0.1%
top 65.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab13.617.2.9+2
NVDgitlab/gitlab13.6.017.2.9+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-9631: An issue was discovered in GitLab CE/EE affecting all versions starting from 132025-02-05
GHSA
GHSA-rfm6-5393-x9wf: An issue was discovered in GitLab CE/EE affecting all versions starting from 132025-02-05

📋Vendor Advisories

2
GitLab
CVE-2024-9631: An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting fr2025-02-05
Debian
CVE-2024-9631: gitlab - An issue was discovered in GitLab CE/EE affecting all versions starting from 13....2024

🕵️Threat Intelligence

1
Bleepingcomputer
GitLab warns of critical arbitrary branch pipeline execution flaw2024-10-10