MEDIUM

CVE-2021-22246

Gitlab GitLab 2021-08-20 CVSS v3.1
CVSS
6.5

Description

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

Summary dbcve.org

GitLab versions before 14.0.2, 13.12.6, and 13.11.6 contain a vulnerability in the Webhook feature that allows authenticated users to abuse webhook functionality to launch denial of service attacks, likely through excessive webhook creation or triggering that consumes excessive server resources.

Mitigation

Update GitLab to version 14.0.2, 13.12.6, or 13.11.6 or later. As a compensating control, restrict webhook creation/modification permissions to trusted users and implement rate limiting on webhook endpoints.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

1.34%
Probability of exploitation in next 30 days
69.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE