An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file.
2024-10-24T10:15:02.717
2024-12-13T15:29:32.850
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 17.3.6 | Yes |
Application | gitlab | gitlab | < 17.3.6 | Yes |
Application | gitlab | gitlab | < 17.4.3 | Yes |
Application | gitlab | gitlab | < 17.4.3 | Yes |
Application | gitlab | gitlab | 17.5.0 | Yes |
Application | gitlab | gitlab | 17.5.0 | Yes |