CVE-2024-2878: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.9.7Fixed in 16.10.5Fixed in 16.11.2 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.9.7 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.10.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.11.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2878?
CVE-2024-2878 has been classified as a denial of service vulnerability.
How do I fix CVE-2024-2878?
To mitigate CVE-2024-2878, upgrade GitLab CE/EE to version 16.9.7, 16.10.5, or 16.11.2 or later.
Which versions are affected by CVE-2024-2878?
CVE-2024-2878 affects GitLab CE/EE versions starting from 15.7 up to 16.9.7 and from 16.10 up to 16.10.5, and from 16.11 up to 16.11.2.
What type of attack does CVE-2024-2878 enable?
CVE-2024-2878 enables attackers to perform a denial of service by using crafted unusual search terms for branch names.
Is there a workaround for CVE-2024-2878?
Currently, the recommended approach to resolve CVE-2024-2878 is to upgrade to a patched version of GitLab CE/EE.