CVE-2024-12379

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.
Configurations

No configuration.

History

12 Feb 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 15:15

Updated : 2025-02-12 15:15


NVD link : CVE-2024-12379

Mitre link : CVE-2024-12379

CVE.ORG link : CVE-2024-12379


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling