MEDIUM

CVE-2021-22259

Gitlab GitLab 2021-10-04 CVSS v3.1
CVSS
6.5

Description

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

Summary dbcve.org

GitLab EE versions 12.6 and later contain a denial-of-service vulnerability in the dependencies API endpoint. The lack of pagination controls allows authenticated users to make unbounded requests for dependency data, potentially exhausting server resources or causing performance degradation.

Mitigation

Implement pagination limits on the dependencies API endpoint and upgrade to a patched GitLab version. Rate-limit API requests as an additional defense-in-depth measure.

EPSS Score

1.03%
Probability of exploitation in next 30 days
62.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE