Home

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.

PUBLISHED Reserved 2024-06-25 | Published 2025-01-09 | Updated 2025-01-09 | Assigner GitLab




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-407: Inefficient Algorithmic Complexity

Product status

Default status
unaffected

17.7 (semver) before 17.7.1
affected

17.6 (semver) before 17.6.3
affected

15.7 (semver) before 17.5.5
affected

Credits

Thanks [xorz](https://hackerone.com/xorz) for reporting this vulnerability through our HackerOne bug bounty program finder

References

gitlab.com/gitlab-org/gitlab/-/issues/468914 (GitLab Issue #468914) issue-tracking permissions-required

about.gitlab.com/...08/patch-release-gitlab-17-7-1-released/

hackerone.com/reports/2553716 (HackerOne Bug Bounty Report #2553716) technical-description exploit permissions-required

cve.org (CVE-2024-6324)

nvd.nist.gov (CVE-2024-6324)

Download JSON