MEDIUM

CVE-2024-2818

Gitlab GitLab 2024-03-28 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows attackers to cause resource exhaustion via a maliciously crafted description parameter for labels, affecting versions before 16.8.5, 16.9.x before 16.9.3, and 16.10.x before 16.10.1.

Mitigation

Upgrade GitLab to version 16.8.5, 16.9.3, 16.10.1 or later to remediate this vulnerability.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.95%
Probability of exploitation in next 30 days
59.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE