HIGH

CVE-2021-22166

Gitlab GitLab 2021-01-15 CVSS v3.1
CVSS
7.5

Description

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

Summary dbcve.org

This vulnerability allows an attacker to cause a denial of service in GitLab's integrated Prometheus monitoring system by sending HTTP requests with malformed methods. The vulnerability affects GitLab version 13.7 and later, potentially causing the Prometheus endpoint to become unresponsive.

Mitigation

Upgrade GitLab to the vendor-patched version. If immediate patching is not feasible, implement network-level filtering or Web Application Firewall (WAF) rules to block malformed HTTP method requests to the Prometheus endpoint.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.38%
Probability of exploitation in next 30 days
70.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE