CVE-2024-13054: Allocation of Resources Without Limits or Throttling in GitLab
An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-13054?
CVE-2024-13054 is classified as a denial of service vulnerability that can potentially cause a system reboot.
How do I fix CVE-2024-13054?
To resolve CVE-2024-13054, upgrade to GitLab CE/EE versions 17.7.7, 17.8.5, or 17.9.2 and above.
Which versions of GitLab are affected by CVE-2024-13054?
CVE-2024-13054 affects all GitLab CE/EE versions prior to 17.7.7, 17.8 before 17.8.5, and 17.9 before 17.9.2.
What types of attacks are possible with CVE-2024-13054?
CVE-2024-13054 allows an attacker to exploit the vulnerability to trigger a denial of service that may lead to system reboot.
Is CVE-2024-13054 present in GitLab Community Edition?
Yes, CVE-2024-13054 impacts both GitLab CE and GitLab EE versions within the specified vulnerabilities.