HIGH

CVE-2024-4025

Gitlab GitLab 2025-06-20 CVSS v3.1
CVSS
7.5

Description

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

Summary dbcve.org

A Denial of Service vulnerability exists in GitLab CE/EE where an attacker can cause a DoS condition by submitting a crafted markdown page. The vulnerability affects all versions from 7.10 prior to 16.11.5, versions 17.0 prior to 17.0.3, and versions 17.1 prior to 17.1.1.

Mitigation

Upgrade GitLab to version 16.11.5, 17.0.3, 17.1.1 or later to patch the vulnerability. If immediate patching is not possible, consider restricting markdown rendering capabilities or implementing rate limiting on markdown processing endpoints.

Weakness (CWE)

CWE-1333

EPSS Score

0.52%
Probability of exploitation in next 30 days
43.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE