CVE-2022-3285
Description
Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab
Summary dbcve.org
GitLab healthcheck endpoint has an allow list mechanism intended to restrict access, but a vulnerability allows unauthorized attackers to bypass this restriction. By exploiting the bypass, an attacker can trigger the healthcheck endpoint in a way that causes denial of service, preventing legitimate access to the GitLab instance.
Mitigation
Upgrade GitLab to version 15.2.5 or later for the 15.2.x branch, 15.3.4 or later for the 15.3.x branch, or 15.4.1 or later for the 15.4.x branch. Alternatively, restrict network-level access to the healthcheck endpoint as a compensating control until patching is possible.