MEDIUM

CVE-2022-2592

Gitlab GitLab 2022-10-17 CVSS v3.1
CVSS
6.5

Description

A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.

Summary dbcve.org

This is a denial of service vulnerability in GitLab CE/EE where missing length validation on Snippet descriptions allows an authenticated attacker to create an excessively large Snippet. When this malicious Snippet is accessed (with or without authentication), it causes excessive server load, potentially leading to service unavailability.

Mitigation

Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2 or later to obtain the patch that adds proper length validation to Snippet descriptions.

Weakness (CWE)

CWE-1284

EPSS Score

1.14%
Probability of exploitation in next 30 days
65.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE