HIGH
CVE-2024-8124
CVSS
7.5
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.
Summary dbcve.org
A Denial of Service vulnerability exists in GitLab CE/EE affecting versions 16.4 through 17.3.1. The issue can be triggered by sending a specific POST request, causing service disruption. The vulnerability is network-exploitable with CVSS 7.5 indicating high availability impact.
Mitigation
Upgrade GitLab to version 17.1.7, 17.2.5, or 17.3.2 or later. For installations on older branches, upgrade to the nearest patched version. Ensure staging/testing environment validation before production deployment.
Weakness (CWE)
CWE-1333
EPSS Score
39.98%
Probability of exploitation in next 30 days
98.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.