MEDIUM
CVE-2021-39877
CVSS
5.5
Description
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
Summary dbcve.org
A vulnerability in GitLab versions 12.2 and later allows attackers to cause uncontrolled resource consumption by uploading a specially crafted file. This is a denial-of-service vulnerability that exploits insufficient handling of certain file types during processing.
Mitigation
Upgrade to the patched version of GitLab as specified in the official GitLab security release. Implement rate limiting and file size restrictions on file uploads as a defense-in-depth measure.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.04%
Probability of exploitation in next 30 days
62.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.