HTTP: GitLab Community and Enterprise Edition Pin Menu Denial of Service

This signature detects attempts to exploit a known vulnerability against GitLab Community and Enterprise Edition. A successful attack can result in a denial-of-service condition.

Extended Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

Affected Products

Gitlab gitlab

References

CVE: CVE-2024-2454

Short Name
HTTP:DOS:GITLAB-CE-PIN-DOS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-2454 Community Denial Edition Enterprise GitLab Menu Pin Service and of
Release Date
08/14/2024
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3765
False Positive
Unknown
Vendors

Gitlab

Found a potential security threat?