MEDIUM
CVE-2024-5423
CVSS
6.5
Description
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.
Summary dbcve.org
GitLab CE/EE versions prior to 17.0.6, 17.1.4, and 17.2.2 contain multiple denial-of-service vulnerabilities in the banzai pipeline component. Attackers can exploit these to cause resource exhaustion by sending specially crafted requests through the pipeline system, potentially rendering the GitLab instance unresponsive.
Mitigation
Upgrade GitLab to version 17.0.7, 17.1.5, 17.2.3, or later to patch the banzai pipeline DoS vulnerabilities.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
0.46%
Probability of exploitation in next 30 days
39.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.