CVE-2024-12379

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.
CVSS

No CVSS.

References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/508559 Exploit Issue Tracking Patch
https://hackerone.com/reports/2871791 Permissions Required
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

06 Aug 2025, 20:17

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
First Time Gitlab gitlab
Gitlab
References () https://gitlab.com/gitlab-org/gitlab/-/issues/508559 - () https://gitlab.com/gitlab-org/gitlab/-/issues/508559 - Exploit, Issue Tracking, Patch
References () https://hackerone.com/reports/2871791 - () https://hackerone.com/reports/2871791 - Permissions Required

12 Feb 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 15:15

Updated : 2025-08-06 20:17


NVD link : CVE-2024-12379

Mitre link : CVE-2024-12379


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-770

Allocation of Resources Without Limits or Throttling