MEDIUM

CVE-2022-1121

Gitlab GitLab 2022-04-04 CVSS v3.1
CVSS
5.3

Description

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

Summary dbcve.org

GitLab Pages lacks appropriate timeout controls, allowing attackers to trigger unlimited resource consumption and cause denial of service by establishing connections that never terminate.

Mitigation

Update GitLab to version 14.7.7, 14.8.5, 14.9.2 or later to receive the timeout configuration patches.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE