CVE-2024-1963: Uncontrolled Resource Consumption in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.
Other sources
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab’s Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, 6.5). It is now mitigated in the latest release and is assigned CVE-2024-1963.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.10.7Fixed in 16.11.4Fixed in 17.0.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.10.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1963?
CVE-2024-1963 has been classified with a medium severity level due to its potential impact on the affected GitLab systems.
How do I fix CVE-2024-1963?
To mitigate CVE-2024-1963, you should update your GitLab installation to the latest version that addresses this vulnerability.
Which versions of GitLab are affected by CVE-2024-1963?
CVE-2024-1963 affects all GitLab CE/EE versions from 8.4 up to but not including 16.10.7, 16.11 up to but not including 16.11.4, and 17.0 up to but not including 17.0.2.
What type of vulnerability is CVE-2024-1963?
CVE-2024-1963 is a vulnerability associated with GitLab's Asana integration that could allow an attacker to exploit regular expression handling.
Is CVE-2024-1963 present in older versions of GitLab?
Yes, CVE-2024-1963 is present in older versions of GitLab starting from 8.4 up to the specified later versions that are affected.