MEDIUM
CVE-2022-3514
CVSS
5.3
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.
Summary dbcve.org
A regular expression denial of service vulnerability exists in GitLab's submodule URL parser. Attackers can craft malicious submodule URLs that cause the regex to enter a catastrophic backtracking scenario, consuming excessive CPU resources and rendering the service unavailable.
Mitigation
Update GitLab to version 15.5.7, 15.6.4, or 15.7.2 or later to patch the vulnerable regex in the submodule URL parser.
Weakness (CWE)
CWE-1333
EPSS Score
0.85%
Probability of exploitation in next 30 days
56.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.