CVE-2024-1816: Uncontrolled Resource Consumption in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1816?
CVE-2024-1816 is classified as a denial of service vulnerability affecting several versions of GitLab.
How do I fix CVE-2024-1816?
To resolve CVE-2024-1816, upgrade GitLab to version 16.11.5 or higher, or to version 17.0.3 or higher, or version 17.1.1 or higher.
Which versions of GitLab are affected by CVE-2024-1816?
The affected GitLab versions are all from 12.0 to below 16.11.5, from 17.0 to below 17.0.3, and 17.1.0.
What type of attack does CVE-2024-1816 enable?
CVE-2024-1816 allows for an attacker to execute a denial of service attack using a specially crafted OpenAPI file.
Is CVE-2024-1816 applicable to both GitLab CE and EE?
Yes, CVE-2024-1816 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) across specified versions.