CVE-2024-6324

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

05 Aug 2025, 15:21

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Summary
  • (es) Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 15.7 hasta la 17.5.5, desde la 17.6 hasta la 17.6.3 y desde la 17.7 hasta la 17.7.1. Era posible desencadenar un ataque de denegación de servicio mediante la creación de referencias cíclicas entre epopeyas.
First Time Gitlab gitlab
Gitlab
References () https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#cyclic-reference-of-epics-leads-resource-exhaustion - () https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#cyclic-reference-of-epics-leads-resource-exhaustion - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/468914 - () https://gitlab.com/gitlab-org/gitlab/-/issues/468914 - Exploit, Issue Tracking
References () https://hackerone.com/reports/2553716 - () https://hackerone.com/reports/2553716 - Permissions Required

09 Jan 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 06:15

Updated : 2025-08-05 15:21


NVD link : CVE-2024-6324

Mitre link : CVE-2024-6324

CVE.ORG link : CVE-2024-6324


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-407

Inefficient Algorithmic Complexity