CVE-2024-2829 is a denial-of-service vulnerability affecting GitLab CE/EE versions 12.5 through 16.9.5, 16.10 through 16.10.3, and 16.11 through 16.11.0. A specially crafted wildcard filter within the FileFinder component can be leveraged to trigger this denial of service. With a CVSS score of 7.5 (High), this vulnerability is network-exploitable with low attack complexity and no user interaction required, leading to a high impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. However, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.5.0, < 16.9.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 12.5.0, < 16.9.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.10.0, < 16.10.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.10.0, < 16.10.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
16.11.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.