VDB
CVE-2024-10307
CVE-2024-10307
PUBLISHED
An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.
EPSS 0.09% · 25.0th percentile
Risk Scores
EPSS Score
0.09%
25.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 12.10.0 |
| Bitnami | gitlab | 12.10.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Mar 26, 2025 CVE Published
- Mar 28, 2025 EPSS Score
- Mar 28, 2025 Coalition ESS Score
- Mar 28, 2025 PoC Published
- Mar 28, 2025 PoC Published
- Mar 29, 2025 Coalition ESS Score
- Apr 10, 2025 EPSS Score
- Apr 23, 2025 EPSS Score
- May 6, 2025 EPSS Score
- May 19, 2025 EPSS Score
- Jun 1, 2025 EPSS Score