Medium severity6.5NVD Advisory· Published Feb 7, 2024· Updated Jun 17, 2026
CVE-2024-1066
CVE-2024-1066
Description
An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL vulnerabilitiesCountByDay
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: >=13.3.0,<16.6.7
- (no CPE)range: from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2
- Range: from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2
Patches
Vulnerability mechanics
References
1- gitlab.com/gitlab-org/gitlab/-/issues/420341nvdIssue TrackingVendor Advisory
News mentions
1- GitLab Security Release: 16.8.2, 16.7.5, 16.6.7GitLab Security Releases · Feb 7, 2024