CVE-2024-8124: Inefficient Regular Expression Complexity in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8124?
CVE-2024-8124 has a severity rating that indicates it can lead to a Denial of Service under specific conditions.
How do I fix CVE-2024-8124?
To mitigate CVE-2024-8124, upgrade to GitLab versions 17.1.7, 17.2.5, or 17.3.2 or later.
Which versions of GitLab are affected by CVE-2024-8124?
CVE-2024-8124 affects all GitLab versions from 16.4 to prior versions of 17.1.7, 17.2 to prior versions of 17.2.5, and 17.3 to prior versions of 17.3.2.
What causes the vulnerability in CVE-2024-8124?
CVE-2024-8124 is caused by a specific POST request that leads to a Denial of Service.
What type of vulnerability is CVE-2024-8124?
CVE-2024-8124 is categorized as a Denial of Service vulnerability.