HTTP: GitLab Community and Enterprise Edition Denial of Service

This signature detects attempts to exploit a known vulnerability against GitLab Community and Enterprise Edition. A successful attack can result in a denial-of-service condition.

Extended Description

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

Affected Products

Gitlab gitlab

Short Name
HTTP:CTS:GITLAB-CE-EE-DOS
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2023-0921 CVE-2024-2818 CVE-2024-2874 Community Denial Edition Enterprise GitLab Service and of
Release Date
01/29/2024
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3764
False Positive
Rarely
Vendors

Gitlab

Found a potential security threat?