MEDIUM
CVE-2024-1816
CVSS
5.5
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.
Summary dbcve.org
GitLab CE/EE versions prior to 16.11.5, 17.0.3, and 17.1.1 contain a denial of service vulnerability in the OpenAPI file parsing functionality. An attacker can upload or process a specially crafted OpenAPI file that causes excessive resource consumption or service disruption.
Mitigation
Upgrade GitLab to version 16.11.5, 17.0.3, 17.1.1 or later. Until patched, restrict OpenAPI file import/upload functionality to trusted, authenticated users only.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
0.29%
Probability of exploitation in next 30 days
21.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.