Uncontrolled CPU Consumption Vulnerability in GitLab EE/CE
CVE-2024-10307
Key Information:
Badges
Summary
A vulnerability has been identified in GitLab EE and CE, which allows an attacker to craft a malicious file that, when accessed through a merge request, triggers excessive CPU usage. This issue affects various versions of GitLab, allowing remote exploitation that can severely impact system performance and availability. Users are urged to upgrade to the latest versions to mitigate the risk associated with this vulnerability.
Affected Version(s)
GitLab 12.10 < 17.8.6
GitLab 17.9 < 17.9.3
GitLab 17.10 < 17.10.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved