Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
5.2 before 18.2.8
18.3 before 18.3.4
18.4 before 18.4.2
Credits
Thanks [ppee](https://hackerone.com/ppee) for reporting this vulnerability through our HackerOne bug bounty program
References
about.gitlab.com/...08/patch-release-gitlab-18-4-2-released/
gitlab.com/gitlab-org/gitlab/-/issues/528979 (GitLab Issue #528979)
hackerone.com/reports/3058791 (HackerOne Bug Bounty Report #3058791)