CVE-2024-4557
Last modified
CVE-2024-4557 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 1.0.0, < 16.11.5 |
| Gitlab | Gitlab | >= 17.0.0, < 17.0.3 |
| Gitlab | Gitlab | 17.1.0 |
References
- https://hackerone.com/reports/2485172Permissions Required
- https://hackerone.com/reports/2485172Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-4557?
How severe is CVE-2024-4557?
How do I fix CVE-2024-4557?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45564Memory corruption during concurrent access to server info ob…7.8
- CVE-2024-45565Memory corruption when blob structure is modified by user-sp…7
- CVE-2024-45566Memory corruption during concurrent buffer access due to mod…7.8
- CVE-2024-45567Memory corruption while encoding JPEG format.7.8
- CVE-2024-45568Memory corruption due to improper bounds check while command…7.8
- CVE-2024-45569Memory corruption while parsing the ML IE due to invalid fra…9.8
- CVE-2024-45570Memory corruption may occur during IO configuration processi…7.8
- CVE-2024-45571Memory corruption may occour occur when stopping the WLAN in…7.8
- CVE-2024-45573Memory corruption may occour while generating test pattern d…7.8
- CVE-2024-45574Memory corruption during array access in Camera kernel due t…7.8
- CVE-2024-45575Memory corruption Camera kernel when large number of devices…7.8
- CVE-2024-45576Memory corruption while prociesing command buffer buffer in …7.8
Are you affected by CVE-2024-4557?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
