MEDIUM
CVE-2024-1066
CVSS
6.5
Description
An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`
Summary dbcve.org
A resource exhaustion vulnerability in GitLab EE's GraphQL API endpoint 'vulnerabilitiesCountByDay' allows authenticated attackers to overwhelm server resources by exploiting insufficient input validation or query limits on this endpoint, causing denial of service.
Mitigation
Upgrade GitLab EE to version 16.6.7, 16.7.5, 16.8.2 or later. As a compensating control, implement rate limiting on GraphQL endpoints at the load balancer or reverse proxy level.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.63%
Probability of exploitation in next 30 days
48.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.