First published: Wed Jun 26 2024(Updated: )
An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.0<16.11.5 | |
GitLab | >=12.0<16.11.5 | |
GitLab | >=17.0.0<17.0.3 | |
GitLab | >=17.0.0<17.0.3 | |
GitLab | =17.1.0 | |
GitLab | =17.1.0 |
Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1816 is classified as a denial of service vulnerability affecting several versions of GitLab.
To resolve CVE-2024-1816, upgrade GitLab to version 16.11.5 or higher, or to version 17.0.3 or higher, or version 17.1.1 or higher.
The affected GitLab versions are all from 12.0 to below 16.11.5, from 17.0 to below 17.0.3, and 17.1.0.
CVE-2024-1816 allows for an attacker to execute a denial of service attack using a specially crafted OpenAPI file.
Yes, CVE-2024-1816 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) across specified versions.