First published: Thu Aug 08 2024(Updated: )
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.6.0<17.0.6 | |
GitLab | >=12.6.0<17.0.6 | |
GitLab | >=17.1.0<17.1.4 | |
GitLab | >=17.1.0<17.1.4 |
Upgrade to versions 17.2.2, 17.1.4, 17.0.6 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4210 has been classified as a Denial of Service (DoS) vulnerability.
To address CVE-2024-4210, upgrade GitLab to versions 17.0.6, 17.1.4, or 17.2.2 or later.
CVE-2024-4210 affects GitLab CE/EE versions starting from 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2.
Yes, an attacker can exploit CVE-2024-4210 remotely using crafted adoc files.
Yes, GitLab has released official patches in the updated versions to fix CVE-2024-4210.