MEDIUM
CVE-2022-1121
CVSS
5.3
Description
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.
Summary dbcve.org
GitLab Pages lacks appropriate timeout controls, allowing attackers to trigger unlimited resource consumption and cause denial of service by establishing connections that never terminate.
Mitigation
Update GitLab to version 14.7.7, 14.8.5, 14.9.2 or later to receive the timeout configuration patches.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
1.08%
Probability of exploitation in next 30 days
63.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.