MEDIUM
CVE-2021-39917
CVSS
6.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack.
Summary dbcve.org
A regular expression in GitLab's quick actions feature suffers from catastrophic backtracking (ReDoS vulnerability), allowing attackers to cause denial of service by providing specially crafted input that triggers exponential regex processing time.
Mitigation
Upgrade to GitLab 14.3.6, 14.4.4, 14.5.2 or later versions to patch the vulnerable regex pattern in the quick actions component.
Weakness (CWE)
CWE-697
EPSS Score
1.33%
Probability of exploitation in next 30 days
69.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.