CVE-2024-5423 Information

Description

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6 starting from 17.1 prior to 17.1.4 and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

Reference

https://gitlab.com/gitlab-org/gitlab/-/issues/463807 https://hackerone.com/reports/2518563

Share on: