CVE-2024-10307
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 28, 2025
CWE ID 770
Summary
CVE-2024-10307: A significant vulnerability has been identified in GitLab Enterprise Edition (EE) and Community Edition (CE) affecting versions prior to 17.8.6, 17.9.3, and 17.10.1. Malicious files can trigger uncontrolled CPU consumption when viewed in association with merge requests, potentially leading to denial-of-service conditions and impacting system performance. Users are strongly advised to update their GitLab installations to the latest patched versions promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab