MEDIUM

CVE-2024-5423

Gitlab GitLab 2024-08-08 CVSS v3.1
CVSS
6.5

Description

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

Summary dbcve.org

GitLab CE/EE versions prior to 17.0.6, 17.1.4, and 17.2.2 contain multiple denial-of-service vulnerabilities in the banzai pipeline component. Attackers can exploit these to cause resource exhaustion by sending specially crafted requests through the pipeline system, potentially rendering the GitLab instance unresponsive.

Mitigation

Upgrade GitLab to version 17.0.7, 17.1.5, 17.2.3, or later to patch the banzai pipeline DoS vulnerabilities.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.46%
Probability of exploitation in next 30 days
39.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE