MEDIUM
CVE-2021-22217
CVSS
6.5
Description
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE allows attackers to cause uncontrolled resource consumption by submitting specially crafted issues or merge requests, potentially rendering the service unavailable.
Mitigation
Upgrade GitLab to version 13.12.2, 13.11.5, or 13.10.5 or later to patch the vulnerability.
EPSS Score
1.85%
Probability of exploitation in next 30 days
78.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.