HIGH
CVE-2022-2931
CVSS
7.5
Description
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.
Summary dbcve.org
A denial-of-service vulnerability in GitLab CE/EE allows attackers to trigger high CPU usage by inserting malformed content into issue descriptions. The vulnerability affects all versions before 15.1.6, 15.2.x before 15.2.4, and 15.3.x before 15.3.2.
Mitigation
Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2 or later. As a temporary measure, restrict issue creation/editing permissions to trusted users until patching is complete.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.16%
Probability of exploitation in next 30 days
65.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.