CVE-2024-10307

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 28, 2025
CWE ID 770

Summary

CVE-2024-10307: A significant vulnerability has been identified in GitLab Enterprise Edition (EE) and Community Edition (CE) affecting versions prior to 17.8.6, 17.9.3, and 17.10.1. Malicious files can trigger uncontrolled CPU consumption when viewed in association with merge requests, potentially leading to denial-of-service conditions and impacting system performance. Users are strongly advised to update their GitLab installations to the latest patched versions promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share