Back

MEDIUM

Allocation of Resources Without Limits or Throttling in GitLab

Published Dec 12, 2024

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

Affected products

Remediation

Vendor solution

Upgrade to versions 17.6.2, 17.5.4, 17.4.6 or above.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Dec 12, 2024
Updated Dec 12, 2024
Reserved Sep 30, 2024
CISA Vulnrichment
Updated Dec 12, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a