HIGH
CVE-2024-8177
CVSS
7.5
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.
Summary dbcve.org
GitLab CE/EE contains a denial of service vulnerability in its Harbor registry integration functionality. When GitLab attempts to integrate with a malicious or compromised Harbor registry, the registry can cause GitLab to become unresponsive or crash, likely through malformed responses that trigger resource exhaustion or processing loops.
Mitigation
Upgrade GitLab to versions 17.4.5, 17.5.3, 17.6.1 or later. Until upgraded, avoid integrating with untrusted or third-party Harbor registries.
Weakness (CWE)
CWE-407
EPSS Score
0.57%
Probability of exploitation in next 30 days
45.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.