Unrated severityNVD Advisory· Published May 9, 2024· Updated Oct 3, 2024
Allocation of Resources Without Limits or Throttling in GitLab
CVE-2024-4539
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.
Affected products
3- Range: >=15.4, <16.9.7; >=16.10, <16.10.5; >=16.11, <16.11.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gitlab.com/gitlab-org/gitlab/-/issues/454815mitreissue-trackingpermissions-required
News mentions
1- GitLab Patch Release: 16.11.2, 16.10.5, 16.9.7GitLab Security Releases · May 8, 2024