An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
ssvc
|
Wed, 05 Feb 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names. | |
Title | Allocation of Resources Without Limits or Throttling in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-770 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published: 2025-02-05T12:21:10.806Z
Updated: 2025-02-05T20:11:02.837Z
Reserved: 2024-03-25T21:02:01.093Z
Link: CVE-2024-2878

Updated: 2025-02-05T13:59:58.532Z

Status : Received
Published: 2025-02-05T13:15:22.523
Modified: 2025-02-05T20:15:44.637
Link: CVE-2024-2878

No data.