Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.
Problem types
CWE-407: Inefficient Algorithmic Complexity
Product status
17.7 (semver) before 17.7.1
17.6 (semver) before 17.6.3
15.7 (semver) before 17.5.5
Credits
Thanks [xorz](https://hackerone.com/xorz) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/468914 (GitLab Issue #468914)
about.gitlab.com/...08/patch-release-gitlab-17-7-1-released/
hackerone.com/reports/2553716 (HackerOne Bug Bounty Report #2553716)