MEDIUM

CVE-2021-22168

Gitlab GitLab 2021-01-15 CVSS v3.1
CVSS
6.5

Description

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

Summary dbcve.org

A regular expression denial of service (ReDoS) vulnerability exists in the NuGet API component of GitLab, affecting all versions starting from 12.8. The vulnerable regex can be triggered by specially crafted input to cause excessive computation, leading to service degradation or unavailability.

Mitigation

Upgrade GitLab to the latest version that includes the patched NuGet API component, or apply the specific security patch for this vulnerability.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1%
Probability of exploitation in next 30 days
61.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE