MEDIUM
CVE-2022-2455
CVSS
6.5
Description
A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.
Summary dbcve.org
A business logic flaw in GitLab's project import functionality allowed authenticated users to import specially crafted malicious projects that caused excessive resource consumption, leading to denial of service through server resource exhaustion.
Mitigation
Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2 or later to receive the patched code that properly validates and handles large repository imports.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.08%
Probability of exploitation in next 30 days
63.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.