HIGH

CVE-2024-8177

Gitlab GitLab 2024-11-26 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

Summary dbcve.org

GitLab CE/EE contains a denial of service vulnerability in its Harbor registry integration functionality. When GitLab attempts to integrate with a malicious or compromised Harbor registry, the registry can cause GitLab to become unresponsive or crash, likely through malformed responses that trigger resource exhaustion or processing loops.

Mitigation

Upgrade GitLab to versions 17.4.5, 17.5.3, 17.6.1 or later. Until upgraded, avoid integrating with untrusted or third-party Harbor registries.

Weakness (CWE)

CWE-407

EPSS Score

0.57%
Probability of exploitation in next 30 days
45.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE