Unrated severityNVD Advisory· Published Mar 28, 2024· Updated Oct 3, 2024
Allocation of Resources Without Limits or Throttling in GitLab
CVE-2024-2818
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.
Affected products
3- Range: <16.8.5, >=16.9 <16.9.3, >=16.10 <16.10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gitlab.com/gitlab-org/gitlab/-/issues/434803mitreissue-trackingpermissions-required
News mentions
1- GitLab Security Release: 16.10.1, 16.9.3, 16.8.5GitLab Security Releases · Mar 27, 2024