MEDIUM

CVE-2021-39877

Gitlab GitLab 2021-10-04 CVSS v3.1
CVSS
5.5

Description

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

Summary dbcve.org

A vulnerability in GitLab versions 12.2 and later allows attackers to cause uncontrolled resource consumption by uploading a specially crafted file. This is a denial-of-service vulnerability that exploits insufficient handling of certain file types during processing.

Mitigation

Upgrade to the patched version of GitLab as specified in the official GitLab security release. Implement rate limiting and file size restrictions on file uploads as a defense-in-depth measure.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.04%
Probability of exploitation in next 30 days
62.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE