MEDIUM

CVE-2024-4210

Gitlab GitLab 2024-08-08 CVSS v3.1
CVSS
6.5

Description

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

Summary dbcve.org

A Denial of Service vulnerability exists in GitLab CE/EE where crafted AsciiDoc (.adoc) files can trigger a DoS condition. The vulnerability affects all versions from 12.6 through the unpatched versions of 17.0.x, 17.1.x, and 17.2.x.

Mitigation

Upgrade GitLab to version 17.0.6, 17.1.4, 17.2.2 or later to remediate this vulnerability.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.5%
Probability of exploitation in next 30 days
42th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE