Denial of Service Vulnerability in GitLab by GitLab Inc.
CVE-2024-13054
Key Information:
Badges
Summary
In GitLab CE/EE, a denial of service vulnerability has been identified, impacting systems running versions prior to 17.7.7, 17.8 from 17.8.0 to 17.8.4, and 17.9 from 17.9.0 to 17.9.1. This vulnerability could potentially allow an attacker to initiate a system reboot under specific conditions, posing significant risks to service availability. It is crucial for users to update their instances to mitigate any risks associated with this issue.
Affected Version(s)
GitLab 0 < 17.7.7
GitLab 17.8 < 17.8.5
GitLab 17.9 < 17.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved