First published: Thu Apr 25 2024(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. A crafted wildcard filter in FileFinder may lead to a denial of service.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.5.0<16.9.6 | |
GitLab | >=12.5.0<16.9.6 | |
GitLab | >=16.10.0<16.10.4 | |
GitLab | >=16.10.0<16.10.4 | |
GitLab | =16.11.0 | |
GitLab | =16.11.0 |
Upgrade to versions 16.9.6, 16.10.4, 16.11.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2829 has been categorized as a denial of service vulnerability affecting multiple versions of GitLab.
To mitigate CVE-2024-2829, upgrade GitLab to version 16.9.6, 16.10.4, or 16.11.1 or later.
CVE-2024-2829 affects all GitLab versions from 12.5 to 16.9.6, 16.10 to 16.10.4, and 16.11 up to 16.11.0.
CVE-2024-2829 enables a crafted wildcard filter in FileFinder that may lead to denial of service.
CVE-2024-2829 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.