GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 9.0, < 18.7.5
- >= 18.8, < 18.8.5
- >= 18.9, < 18.9.1
A denial-of-service vulnerability has been identified in the GitLab CI trigger API, affecting GitLab Community Edition (CE) and Enterprise Edition (EE) versions 9.0 prior to 18.7.5, 18.8 prior to 18.8.5, and 18.9 prior to 18.9.1. Under certain circumstances, this vulnerability allowed an authenticated user with specific access to create specially crafted CI triggers via the API, leading to a denial-of-service condition.
Exploitation of this vulnerability could cause a denial-of-service condition, disrupting normal operations by overwhelming the system or causing it to become unresponsive.
GitLab has released patch versions 18.9.1, 18.8.5, and 18.7.5, which include the necessary fix for this vulnerability. Users are strongly recommended to upgrade to one of these versions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.