Advisory Details

April 1st, 2024

GitLab Label Description Uncontrolled Resource Consumption Denial-of-Service Vulnerability

ZDI-24-358
ZDI-CAN-21883

CVE ID CVE-2024-2818
CVSS SCORE 4.3, AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
AFFECTED VENDORS GitLab
AFFECTED PRODUCTS GitLab
VULNERABILITY DETAILS

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of GitLab. Authentication is required to exploit this vulnerability.

The specific flaw exists within the handling of label descriptions. By sending a crafted request, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

ADDITIONAL DETAILS GitLab has issued an update to correct this vulnerability. More details can be found at:
https://about.gitlab.com/releases/2024/03/27/security-release-gitlab-16-10-1-released/#DOS%20using%20crafted%20emojis
DISCLOSURE TIMELINE
  • 2023-08-09 - Vulnerability reported to vendor
  • 2024-04-01 - Coordinated public release of advisory
CREDIT Quintin Crist of Trend Micro Security Research
BACK TO ADVISORIES