Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7610


A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.


Published

2024-08-08T11:15:13.857

Last Modified

2024-08-29T15:45:27.523

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 17.0.6 Yes
Application gitlab gitlab < 17.0.6 Yes
Application gitlab gitlab < 17.1.4 Yes
Application gitlab gitlab < 17.1.4 Yes
Application gitlab gitlab < 17.2.2 Yes
Application gitlab gitlab < 17.2.2 Yes

References