CVE-2024-4557: Uncontrolled Resource Consumption in GitLab
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.
Other sources
Multiple Denial of Service (DoS) issues has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, 6.5). It is now mitigated in the latest release and is assigned CVE-2024-4557.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.5Fixed in 17.0.3Fixed in 17.1.1 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.11.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 17.0.3 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 17.1.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4557?
CVE-2024-4557 is considered a high severity vulnerability that allows multiple Denial of Service (DoS) conditions in GitLab.
How do I fix CVE-2024-4557?
To fix CVE-2024-4557, users should upgrade to GitLab version 16.11.5 or later, 17.0.3 or later, or 17.1.1 or later.
What versions of GitLab are affected by CVE-2024-4557?
CVE-2024-4557 affects all versions of GitLab starting from 1.0 up to 16.11.5, 17.0 up to 17.0.3, and 17.1 up to 17.1.1.
What types of attacks can be executed due to CVE-2024-4557?
CVE-2024-4557 allows an attacker to execute Denial of Service (DoS) attacks that can lead to resource exhaustion.
Is CVE-2024-4557 applicable to both GitLab CE and EE?
Yes, CVE-2024-4557 is applicable to both GitLab Community Edition (CE) and Enterprise Edition (EE) across the specified versions.