HIGH

CVE-2024-11828

Gitlab GitLab 2024-11-26 CVSS v3.1
CVSS
7.5

Description

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch.

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows attackers to crash the service via crafted API calls. This affects all versions from 13.2.4 through the vulnerable ranges (17.4.x before 17.4.5, 17.5.x before 17.5.3, and 17.6.x before 17.6.1). The flaw is a regression of a previously patched issue.

Mitigation

Upgrade GitLab to version 17.4.5, 17.5.3, 17.6.1 or later to resolve this DoS vulnerability.

Weakness (CWE)

CWE-407

EPSS Score

0.61%
Probability of exploitation in next 30 days
47.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE