MEDIUM

CVE-2024-1066

Gitlab GitLab 2024-02-07 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

Summary dbcve.org

A resource exhaustion vulnerability in GitLab EE's GraphQL API endpoint 'vulnerabilitiesCountByDay' allows authenticated attackers to overwhelm server resources by exploiting insufficient input validation or query limits on this endpoint, causing denial of service.

Mitigation

Upgrade GitLab EE to version 16.6.7, 16.7.5, 16.8.2 or later. As a compensating control, implement rate limiting on GraphQL endpoints at the load balancer or reverse proxy level.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.63%
Probability of exploitation in next 30 days
48.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE