MEDIUM

CVE-2021-22217

Gitlab GitLab 2021-06-08 CVSS v3.1
CVSS
6.5

Description

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows attackers to cause uncontrolled resource consumption by submitting specially crafted issues or merge requests, potentially rendering the service unavailable.

Mitigation

Upgrade GitLab to version 13.12.2, 13.11.5, or 13.10.5 or later to patch the vulnerability.

EPSS Score

1.85%
Probability of exploitation in next 30 days
78.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE