CVE-2024-8041: Uncontrolled Resource Consumption in GitLab
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8041?
CVE-2024-8041 is classified as a Denial of Service (DoS) vulnerability in GitLab.
How do I fix CVE-2024-8041?
To mitigate CVE-2024-8041, upgrade to GitLab versions 17.1.6, 17.2.4 or 17.3.1 and later.
What versions of GitLab are affected by CVE-2024-8041?
CVE-2024-8041 affects all GitLab versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1.
Can CVE-2024-8041 be exploited remotely?
Yes, CVE-2024-8041 can be exploited remotely upon importing a maliciously crafted repository via the GitHub importer.
What type of attack does CVE-2024-8041 facilitate?
CVE-2024-8041 facilitates a Denial of Service attack, potentially incapacitating the GitLab service.