MEDIUM
CVE-2022-1185
CVSS
6.5
Description
A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE allows remote attackers to crash the web application by uploading a maliciously crafted RDoc file. The vulnerability exists in the RDoc rendering component across versions 10 through 14.9.2, where specially crafted documentation files trigger a crash condition.
Mitigation
Upgrade GitLab to version 14.7.8, 14.8.6, 14.9.3, or later. If immediate upgrade is not possible, disable or restrict the RDoc rendering feature and file upload capabilities as a compensating control.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
1.33%
Probability of exploitation in next 30 days
69.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.