CVE-2024-4210: Uncontrolled Resource Consumption in GitLab
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4210?
CVE-2024-4210 has been classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2024-4210?
To address CVE-2024-4210, upgrade GitLab to versions 17.0.6, 17.1.4, or 17.2.2 or later.
What versions of GitLab are affected by CVE-2024-4210?
CVE-2024-4210 affects GitLab CE/EE versions starting from 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2.
Can CVE-2024-4210 be exploited remotely?
Yes, an attacker can exploit CVE-2024-4210 remotely using crafted adoc files.
Is there an official patch for CVE-2024-4210?
Yes, GitLab has released official patches in the updated versions to fix CVE-2024-4210.