HIGH

CVE-2022-2931

Gitlab GitLab 2022-10-17 CVSS v3.1
CVSS
7.5

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

Summary dbcve.org

A denial-of-service vulnerability in GitLab CE/EE allows attackers to trigger high CPU usage by inserting malformed content into issue descriptions. The vulnerability affects all versions before 15.1.6, 15.2.x before 15.2.4, and 15.3.x before 15.3.2.

Mitigation

Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2 or later. As a temporary measure, restrict issue creation/editing permissions to trusted users until patching is complete.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.16%
Probability of exploitation in next 30 days
65.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE