MEDIUM

CVE-2021-39912

Gitlab GitLab 2021-11-05 CVSS v3.1
CVSS
5.3

Description

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

Summary dbcve.org

A denial of service vulnerability exists in GitLab CE/EE versions 13.7 and later where processing a malformed TIFF image can trigger memory exhaustion, potentially causing the service to become unavailable.

Mitigation

Update GitLab to the patched version (contact GitLab for specific fixed version) or implement temporary image upload restrictions until patching is feasible.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

1.48%
Probability of exploitation in next 30 days
72.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE