VDB

CVE-2024-12379

CVE-2024-12379 PUBLISHED

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

EPSS 0.06% · 19.4th percentile

Risk Scores

EPSS Score
0.06%
19.4th percentile

Affected Products

VendorProductVersions
Bitnamigitlab14.1.0
Bitnamigitlab14.1.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Feb 11, 2025 CVE Published
  • Feb 12, 2025 Coalition ESS Score
  • Feb 12, 2025 PoC Published
  • Feb 12, 2025 PoC Published
  • Feb 13, 2025 EPSS Score
  • Feb 27, 2025 EPSS Score
  • Mar 5, 2025 CVE Updated
  • Mar 14, 2025 EPSS Score
  • Mar 28, 2025 EPSS Score
  • Apr 12, 2025 EPSS Score
  • Apr 26, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›