An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.
Fixes

Solution

Upgrade to versions 16.10.7, 16.11.4, 17.0.2 or above.


Workaround

No workaround given by the vendor.

History

Fri, 30 Aug 2024 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-08-30T13:24:42.721Z

Reserved: 2024-02-28T00:02:44.123Z

Link: CVE-2024-1963

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.389Z

cve-icon NVD

Status : Modified

Published: 2024-06-12T23:15:49.670

Modified: 2024-11-21T08:51:41.757

Link: CVE-2024-1963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.