CVE-2021-39942
Description
A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.
Summary dbcve.org
This vulnerability allows low-privileged users to bypass file size limits when uploading NPM packages to the GitLab package registry. By circumventing these restrictions, an attacker can upload abnormally large packages, potentially consuming excessive storage and bandwidth resources leading to denial of service.
Mitigation
Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later to patch the vulnerability. Additionally, review and enforce file size limits at the infrastructure level as a defense-in-depth measure.