CVE-2024-2829: Unauthenticated ReDoS in FileFinder when using wildcard filters in project file search
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. A crafted wildcard filter in FileFinder may lead to a denial of service.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2829?
CVE-2024-2829 has been categorized as a denial of service vulnerability affecting multiple versions of GitLab.
How do I fix CVE-2024-2829?
To mitigate CVE-2024-2829, upgrade GitLab to version 16.9.6, 16.10.4, or 16.11.1 or later.
What versions of GitLab are affected by CVE-2024-2829?
CVE-2024-2829 affects all GitLab versions from 12.5 to 16.9.6, 16.10 to 16.10.4, and 16.11 up to 16.11.0.
What type of attack does CVE-2024-2829 enable?
CVE-2024-2829 enables a crafted wildcard filter in FileFinder that may lead to denial of service.
Is CVE-2024-2829 specific to GitLab CE or EE?
CVE-2024-2829 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.