CVE-2024-2818: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2818?
CVE-2024-2818 is categorized as a medium severity vulnerability affecting specific versions of GitLab.
How do I fix CVE-2024-2818?
To mitigate the effects of CVE-2024-2818, upgrade GitLab to version 16.8.5 or later, or to 16.9.3 or later.
Which GitLab versions are affected by CVE-2024-2818?
CVE-2024-2818 affects all versions of GitLab before 16.8.5, and versions starting from 16.9 before 16.9.3, as well as 16.10.0.
What type of attack is associated with CVE-2024-2818?
CVE-2024-2818 allows attackers to conduct a denial of service attack via a maliciously crafted description parameter.
Is there a workaround for CVE-2024-2818?
There are no known workarounds for CVE-2024-2818; upgrading to a patched version is the recommended approach.