MEDIUM

CVE-2022-1954

Gitlab GitLab 2022-07-01 CVSS v3.1
CVSS
5.3

Description

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

Summary dbcve.org

A Regular Expression Denial of Service (ReDoS) vulnerability in GitLab CE/EE allows specially crafted web server response headers to trigger inefficient regex processing, causing excessive CPU consumption that renders the GitLab instance inaccessible.

Mitigation

Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later to patch the vulnerable regex pattern in header processing.

Weakness (CWE)

CWE-1333

EPSS Score

1.03%
Probability of exploitation in next 30 days
62.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE