MEDIUM

CVE-2021-22181

Gitlab GitLab 2021-06-11 CVSS v3.1
CVSS
6.5

Description

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows authenticated attackers to create recursive pipeline relationships where pipelines reference each other in a cycle, causing excessive resource consumption and rendering the system unavailable.

Mitigation

Upgrade GitLab to the patched version. Additionally, review existing pipeline configurations for circular dependencies and implement pipeline resource limits where possible.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.06%
Probability of exploitation in next 30 days
63th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE