CVE-2024-12379

MEDIUM

Gitlab < 17.6.5 - Resource Allocation Without Limits

Title source: rule

Description

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-770
Status published

Affected Products (2)

gitlab/gitlab < 17.6.5
gitlab/gitlab < 17.6.5

Timeline

Published Feb 12, 2025
Tracked Since Feb 18, 2026