MEDIUM

CVE-2021-39942

Gitlab GitLab 2022-01-18 CVSS v3.1
CVSS
6.5

Description

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

Summary dbcve.org

This vulnerability allows low-privileged users to bypass file size limits when uploading NPM packages to the GitLab package registry. By circumventing these restrictions, an attacker can upload abnormally large packages, potentially consuming excessive storage and bandwidth resources leading to denial of service.

Mitigation

Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later to patch the vulnerability. Additionally, review and enforce file size limits at the infrastructure level as a defense-in-depth measure.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.45%
Probability of exploitation in next 30 days
72.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE