CVE-2024-8973: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8973?
CVE-2024-8973 is classified as a high-severity vulnerability due to its potential to cause a denial of service (DoS) condition.
How do I fix CVE-2024-8973?
To fix CVE-2024-8973, upgrade your GitLab CE/EE to version 17.9.8 or newer, 17.10.6 or newer, or 17.11.2 or newer.
What versions are affected by CVE-2024-8973?
CVE-2024-8973 affects GitLab CE/EE versions from 17.1 to 17.9.8, from 17.10 to 17.10.6, and from 17.11 to 17.11.2.
What type of attack does CVE-2024-8973 enable?
CVE-2024-8973 enables a denial of service attack via maliciously crafted payloads in GitHub import requests.
Is CVE-2024-8973 present in GitLab SaaS installations?
CVE-2024-8973 does not affect GitLab SaaS installations as it is limited to self-hosted GitLab CE/EE versions.