{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-9631","assignerOrgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","state":"PUBLISHED","assignerShortName":"GitLab","dateReserved":"2024-10-08T13:02:18.165Z","datePublished":"2025-02-05T10:30:51.252Z","dateUpdated":"2025-02-05T19:26:24.166Z"},"containers":{"cna":{"title":"Inefficient Algorithmic Complexity in GitLab","descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow."}],"affected":[{"vendor":"GitLab","product":"GitLab","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"13.6","status":"affected","lessThan":"17.2.9","versionType":"semver"},{"version":"17.3","status":"affected","lessThan":"17.3.5","versionType":"semver"},{"version":"17.4","status":"affected","lessThan":"17.4.2","versionType":"semver"}],"defaultStatus":"unaffected"}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-407: Inefficient Algorithmic Complexity","cweId":"CWE-407","type":"CWE"}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480867","name":"GitLab Issue #480867","tags":["issue-tracking","permissions-required"]},{"url":"https://hackerone.com/reports/2650086","name":"HackerOne Bug Bounty Report #2650086","tags":["technical-description","exploit","permissions-required"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}],"solutions":[{"lang":"en","value":"Upgrade to versions 17.2.9, 17.3.5, 17.4.2 or above."}],"credits":[{"lang":"en","value":"Thanks [a92847865](https://hackerone.com/a92847865) for reporting this vulnerability through our HackerOne bug bounty program","type":"finder"}],"providerMetadata":{"orgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","shortName":"GitLab","dateUpdated":"2025-02-05T10:30:51.252Z"}},"adp":[{"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480867","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-02-05T19:26:20.951787Z","id":"CVE-2024-9631","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-02-05T19:26:24.166Z"}}]}}