High severity7.5NVD Advisory· Published Feb 5, 2025· Updated Jun 17, 2026
CVE-2024-9631
CVE-2024-9631
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.
Affected products
613.6 - 17.2.8, 17.3 - 17.3.4, 17.4 - 17.4.1+ 3 more
- (no CPE)range: 13.6 - 17.2.8, 17.3 - 17.3.4, 17.4 - 17.4.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 13.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.6.0,<17.2.9
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.6.0,<17.2.9
- Range: 13.6 - 17.2.8, 17.3 - 17.3.4, 17.4 - 17.4.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/480867nvdExploitIssue Tracking
- hackerone.com/reports/2650086nvdPermissions Required
News mentions
1- GitLab Critical Patch Release: 17.4.2, 17.3.5, 17.2.9GitLab Security Releases · Oct 9, 2024