CVE-2024-8177: Inefficient Algorithmic Complexity in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8177?
CVE-2024-8177 has been classified as a medium severity vulnerability affecting GitLab.
How do I fix CVE-2024-8177?
To fix CVE-2024-8177, upgrade GitLab to version 17.4.5 or later, 17.5.3 or later, or 17.6.1 or later.
What could happen if I am affected by CVE-2024-8177?
If affected by CVE-2024-8177, exploiting the vulnerability might lead to a Denial of Service for GitLab.
Which versions of GitLab are vulnerable to CVE-2024-8177?
CVE-2024-8177 affects all GitLab versions from 15.6.0 up to but not including 17.4.5, 17.5.3, and 17.6.1.
Is there a workaround for CVE-2024-8177 if I cannot upgrade?
Currently, the recommended approach is to upgrade GitLab, as no specific workaround has been provided for CVE-2024-8177.