MEDIUM
CVE-2021-39907
CVSS
5.3
Description
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.
Summary dbcve.org
A denial of service vulnerability exists in GitLab CE/EE versions 13.7 and later. When processing certain images, the EXIF data stripping functionality consumes excessive CPU resources, potentially rendering the service unavailable due to resource exhaustion.
Mitigation
Update GitLab to a patched version that addresses this vulnerability. Consider implementing rate limiting on image upload endpoints as a compensating control until the patch can be applied.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
1.48%
Probability of exploitation in next 30 days
72.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.