CVE-2024-4025: Inefficient Regular Expression Complexity in GitLab
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4025?
CVE-2024-4025 has been classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2024-4025?
To fix CVE-2024-4025, upgrade to GitLab versions 16.11.5, 17.0.3, or 17.1.1 or later.
Which versions of GitLab are affected by CVE-2024-4025?
GitLab CE/EE versions from 7.10 up to, but not including, 16.11.5; 17.0 prior to 17.0.3; and 17.1 prior to 17.1.1 are affected.
Can CVE-2024-4025 be exploited remotely?
Yes, CVE-2024-4025 can be exploited remotely by an attacker using a specially crafted markdown page.
What type of vulnerability is CVE-2024-4025?
CVE-2024-4025 is a Denial of Service (DoS) condition, which could disrupt the availability of the affected GitLab services.