MEDIUM

CVE-2022-3514

Gitlab GitLab 2023-01-12 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

Summary dbcve.org

A regular expression denial of service vulnerability exists in GitLab's submodule URL parser. Attackers can craft malicious submodule URLs that cause the regex to enter a catastrophic backtracking scenario, consuming excessive CPU resources and rendering the service unavailable.

Mitigation

Update GitLab to version 15.5.7, 15.6.4, or 15.7.2 or later to patch the vulnerable regex in the submodule URL parser.

Weakness (CWE)

CWE-1333

EPSS Score

0.85%
Probability of exploitation in next 30 days
56.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE