CVE-2024-1947: Improper Handling of Highly Compressed Data (Data Amplification) in GitLab
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.
Other sources
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 up to 16.10.6, 16.11 up to 16.11.3, and 17.0 up to 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L, 4.3). It is now mitigated in the latest release and is assigned CVE-2024-1947.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1947?
CVE-2024-1947 is classified as a high severity denial of service (DoS) vulnerability.
How do I fix CVE-2024-1947?
To mitigate CVE-2024-1947, upgrade GitLab to a version that is 16.10.6 or higher, 16.11.3 or higher, or 17.0.1 or higher.
What versions of GitLab are affected by CVE-2024-1947?
CVE-2024-1947 affects GitLab CE/EE versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1.
Can CVE-2024-1947 lead to data loss?
CVE-2024-1947 primarily causes a denial of service, disrupting system availability but not leading to direct data loss.
What types of attacks does CVE-2024-1947 enable?
CVE-2024-1947 enables attackers to create a denial of service condition by sending crafted API calls.