CVE-2024-9367

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/496631 Exploit Issue Tracking Vendor Advisory
https://hackerone.com/reports/2735311 Permissions Required
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

11 Jul 2025, 19:30

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/496631 - () https://gitlab.com/gitlab-org/gitlab/-/issues/496631 - Exploit, Issue Tracking, Vendor Advisory
References () https://hackerone.com/reports/2735311 - () https://hackerone.com/reports/2735311 - Permissions Required
Summary
  • (es) Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.9 hasta la 17.4.6, la 17.5 hasta la 17.5.4 y la 17.6 hasta la 17.6.2, que permite a un atacante provocar un consumo descontrolado de CPU, lo que podría provocar una condición de denegación de servicio (DoS) al analizar plantillas para generar registros de cambios.
First Time Gitlab
Gitlab gitlab
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*

12 Dec 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 12:15

Updated : 2025-07-11 19:30


NVD link : CVE-2024-9367

Mitre link : CVE-2024-9367

CVE.ORG link : CVE-2024-9367


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-770

Allocation of Resources Without Limits or Throttling