ZeroHour

CVE-2024-8124

mass

Unauthenticated Regular-Expression DoS in GitLab CE/EE via crafted POST request

CVSS 3.1
7.5 high
EPSS
40%p99
Published
()
Modified
AI analysis

GitLab CE and EE versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2 contain a denial-of-service flaw classified as inefficient regular expression complexity (CWE-1333). An unauthenticated remote attacker can trigger it by sending a specific, crafted POST request to an affected instance, with no privileges or user interaction required (CVSS AV:N/AC:L/PR:N/UI:N). The impact is limited to availability: the crafted request can consume excessive processing time and degrade or hang the instance (CVSS 7.5 High, with no confidentiality or integrity impact). Any organization running a self-managed GitLab Community Edition or Enterprise Edition instance in those version ranges is affected, while instances running versions older than 16.4 or the patched releases are not. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA KEV, but a 40% EPSS score (99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.

What to do: Upgrade self-managed GitLab CE/EE to 17.1.7, 17.2.5, or 17.3.2, or the latest available release, and verify the running version in the instance's admin interface first. If an immediate upgrade is not possible, restrict unauthenticated network access to the GitLab web/API at the firewall or reverse-proxy layer and apply rate limiting on POST traffic while monitoring for CPU/latency spikes that would indicate DoS attempts. Given the 40% EPSS score, prioritize patching internet-facing instances.

Affected
GitLab CE (Community Edition)All versions starting from 16.4 prior to 17.1.7; starting from 17.2 prior to 17.2.5; starting from 17.3 prior to 17.3.2
GitLab EE (Enterprise Edition)All versions starting from 16.4 prior to 17.1.7; starting from 17.2 prior to 17.2.5; starting from 17.3 prior to 17.3.2
Estimated exposure
mass~100,000+ internet-exposed GitLab instances (order of 10^5); the subset running specifically affected 16.4-17.3 versions is unknown — Public internet-wide scans have long counted self-managed GitLab among the most commonly exposed developer platforms with on the order of hundreds of thousands of internet-facing servers, and self-managed deployments are the primary…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.

Vendors
gitlab
Products
gitlab
Weakness
CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.