MEDIUM

CVE-2022-1185

Gitlab GitLab 2022-04-04 CVSS v3.1
CVSS
6.5

Description

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows remote attackers to crash the web application by uploading a maliciously crafted RDoc file. The vulnerability exists in the RDoc rendering component across versions 10 through 14.9.2, where specially crafted documentation files trigger a crash condition.

Mitigation

Upgrade GitLab to version 14.7.8, 14.8.6, 14.9.3, or later. If immediate upgrade is not possible, disable or restrict the RDoc rendering feature and file upload capabilities as a compensating control.

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

1.33%
Probability of exploitation in next 30 days
69.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE