MEDIUM

CVE-2021-39933

Gitlab GitLab 2021-12-13 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

Summary dbcve.org

A regular expression in GitLab used for parsing user input (notes, comments) is susceptible to catastrophic backtracking, enabling attackers to craft malicious input that causes excessive CPU consumption and denial of service through ReDoS (Regular Expression Denial of Service).

Mitigation

Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later to patch the vulnerable regular expression.

Weakness (CWE)

CWE-1333

EPSS Score

1.42%
Probability of exploitation in next 30 days
71.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE