MEDIUM
CVE-2021-22216
CVSS
6.5
Description
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE allows attackers to cause uncontrolled resource consumption by submitting extremely long issue or merge request descriptions, potentially exhausting server resources.
Mitigation
Upgrade GitLab to version 13.12.2, 13.11.5, or 13.10.5 or later to patch this vulnerability.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.03%
Probability of exploitation in next 30 days
62.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.