CVE-2024-9631 – GitLab CE/EE Slow Diff View Vulnerability

The following table lists the changes that have been made to the
CVE-2024-9631 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 05, 2025

    Action Type Old Value New Value
    Added Description An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-407
    Added Reference https://gitlab.com/gitlab-org/gitlab/-/issues/480867
    Added Reference https://hackerone.com/reports/2650086
Share the Post:

Related Posts