MEDIUM

CVE-2021-39880

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
6.5

Description

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

Summary dbcve.org

A Denial of Service vulnerability exists in the apollo_upload_server Ruby gem used by GitLab CE/EE. Attackers can send specially crafted requests to the apollo_upload_server middleware, causing the service to become unavailable to all users.

Mitigation

Upgrade GitLab to version 14.0.9 or later for 14.0.x branches, 14.1.4 or later for 14.1.x branches, or 14.2.2 or later for 14.2.x branches to patch the vulnerable apollo_upload_server component.

EPSS Score

1.85%
Probability of exploitation in next 30 days
78.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE