MEDIUM

CVE-2024-1816

Gitlab GitLab 2024-06-27 CVSS v3.1
CVSS
5.5

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

Summary dbcve.org

GitLab CE/EE versions prior to 16.11.5, 17.0.3, and 17.1.1 contain a denial of service vulnerability in the OpenAPI file parsing functionality. An attacker can upload or process a specially crafted OpenAPI file that causes excessive resource consumption or service disruption.

Mitigation

Upgrade GitLab to version 16.11.5, 17.0.3, 17.1.1 or later. Until patched, restrict OpenAPI file import/upload functionality to trusted, authenticated users only.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.29%
Probability of exploitation in next 30 days
21.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE