MEDIUM

CVE-2021-22216

Gitlab GitLab 2021-06-08 CVSS v3.1
CVSS
6.5

Description

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows attackers to cause uncontrolled resource consumption by submitting extremely long issue or merge request descriptions, potentially exhausting server resources.

Mitigation

Upgrade GitLab to version 13.12.2, 13.11.5, or 13.10.5 or later to patch this vulnerability.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.03%
Probability of exploitation in next 30 days
62.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE