VDB

CVE-2024-3114

CVE-2024-3114 PUBLISHED

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

EPSS 0.05% · 17.2th percentile

Risk Scores

EPSS Score
0.05%
17.2th percentile

Affected Products

VendorProductVersions
Bitnamigitlab11.10.0, 17.1.0, 17.2.0
Bitnamigitlab11.10.0, 17.1.0, 17.2.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Aug 7, 2024 CVE Published
  • Aug 8, 2024 PoC Published
  • Aug 8, 2024 CVE Updated
  • Aug 13, 2024 EPSS Score
  • Aug 20, 2024 PoC Published
  • Sep 3, 2024 EPSS Score
  • Sep 24, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 14, 2024 EPSS Score
  • Nov 4, 2024 EPSS Score
  • Nov 25, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›