CVE-2024-2800: Uncontrolled Resource Consumption in GitLab
ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2800?
CVE-2024-2800 has been classified with a high severity due to its potential to cause denial of service through Regex backtracking.
How do I fix CVE-2024-2800?
To resolve CVE-2024-2800, upgrade your GitLab to version 17.0.6 or later for branch names matching wildcards.
Which versions are affected by CVE-2024-2800?
CVE-2024-2800 affects all versions of GitLab from 11.3 up to and including 17.0.6, along with specific versions 17.1 up to 17.1.4 and 17.2 up to 17.2.2.
What kind of attack is possible with CVE-2024-2800?
CVE-2024-2800 enables a ReDoS (Regular Expression Denial of Service) attack that can render the application unresponsive.
Is CVE-2024-2800 present in both GitLab EE and CE?
Yes, CVE-2024-2800 affects both GitLab Enterprise Edition (EE) and Community Edition (CE) across the specified versions.