VDB
CVE-2024-3114
CVE-2024-3114
PUBLISHED
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.
EPSS 0.05% · 17.2th percentile
Risk Scores
EPSS Score
0.05%
17.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 11.10.0, 17.1.0, 17.2.0 |
| Bitnami | gitlab | 11.10.0, 17.1.0, 17.2.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Aug 7, 2024 CVE Published
- Aug 8, 2024 PoC Published
- Aug 8, 2024 CVE Updated
- Aug 13, 2024 EPSS Score
- Aug 20, 2024 PoC Published
- Sep 3, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 14, 2024 EPSS Score
- Nov 4, 2024 EPSS Score
- Nov 25, 2024 EPSS Score