CVE-2024-12379

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/508559 Exploit Issue Tracking Patch
https://hackerone.com/reports/2871791 Permissions Required
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

06 Aug 2025, 20:17

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
References () https://gitlab.com/gitlab-org/gitlab/-/issues/508559 - () https://gitlab.com/gitlab-org/gitlab/-/issues/508559 - Exploit, Issue Tracking, Patch
References () https://hackerone.com/reports/2871791 - () https://hackerone.com/reports/2871791 - Permissions Required
First Time Gitlab
Gitlab gitlab
Summary
  • (es) Una vulnerabilidad de denegación de servicio en GitLab CE/EE que afecta a todas las versiones desde la 14.1 anterior a la 17.6.5, la 17.7 anterior a la 17.7.4 y la 17.8 anterior a la 17.8.2 permite a un atacante afectar la disponibilidad de GitLab mediante la creación de símbolos ilimitados por medio del parámetro scopes en un token de acceso personal.

12 Feb 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 15:15

Updated : 2025-08-06 20:17


NVD link : CVE-2024-12379

Mitre link : CVE-2024-12379

CVE.ORG link : CVE-2024-12379


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-770

Allocation of Resources Without Limits or Throttling