MEDIUM

CVE-2022-2455

Gitlab GitLab 2022-10-17 CVSS v3.1
CVSS
6.5

Description

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

Summary dbcve.org

A business logic flaw in GitLab's project import functionality allowed authenticated users to import specially crafted malicious projects that caused excessive resource consumption, leading to denial of service through server resource exhaustion.

Mitigation

Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2 or later to receive the patched code that properly validates and handles large repository imports.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE