CVE-2024-2878

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

06 Aug 2025, 20:17

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Summary
  • (es) Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.7 hasta la 16.9.7, desde la 16.10 hasta la 16.10.5 y desde la 16.11 hasta la 16.11.2. Un atacante podría provocar una denegación de servicio creando términos de búsqueda inusuales para los nombres de las ramas.
First Time Gitlab gitlab
Gitlab
References () https://gitlab.com/gitlab-org/gitlab/-/issues/451918 - () https://gitlab.com/gitlab-org/gitlab/-/issues/451918 - Broken Link
References () https://hackerone.com/reports/2416356 - () https://hackerone.com/reports/2416356 - Permissions Required
References () https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released/ - () https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released/ - Release Notes
CWE NVD-CWE-noinfo

05 Feb 2025, 20:15

Type Values Removed Values Added
References
  • () https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released/ -

05 Feb 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 13:15

Updated : 2025-08-06 20:17


NVD link : CVE-2024-2878

Mitre link : CVE-2024-2878

CVE.ORG link : CVE-2024-2878


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

NVD-CWE-noinfo