Medium severity4.3NVD Advisory· Published Mar 28, 2024· Updated Jun 17, 2026
CVE-2024-2818
CVE-2024-2818
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <16.8.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <16.8.5
- cpe:2.3:a:gitlab:gitlab:16.10.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.10.0:*:*:*:enterprise:*:*:*
- (no CPE)range: <16.8.5, >=16.9 <16.9.3, >=16.10 <16.10.1
- Range: <16.8.5, >=16.9 <16.9.3, >=16.10 <16.10.1
Patches
Vulnerability mechanics
References
1- gitlab.com/gitlab-org/gitlab/-/issues/434803nvdBroken Link
News mentions
1- GitLab Security Release: 16.10.1, 16.9.3, 16.8.5GitLab Security Releases · Mar 27, 2024