HIGH
CVE-2024-11828
CVSS
7.5
Description
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch.
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE allows attackers to crash the service via crafted API calls. This affects all versions from 13.2.4 through the vulnerable ranges (17.4.x before 17.4.5, 17.5.x before 17.5.3, and 17.6.x before 17.6.1). The flaw is a regression of a previously patched issue.
Mitigation
Upgrade GitLab to version 17.4.5, 17.5.3, 17.6.1 or later to resolve this DoS vulnerability.
Weakness (CWE)
CWE-407
EPSS Score
0.61%
Probability of exploitation in next 30 days
47.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.