HIGH
CVE-2022-3639
CVSS
7.5
Description
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.
Summary dbcve.org
A denial-of-service vulnerability in GitLab CE/EE allows attackers to trigger high CPU usage via improper data handling during branch creation, causing service degradation or unavailability.
Mitigation
Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2, or later to resolve the improper data handling in branch creation that causes excessive CPU consumption.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
0.9%
Probability of exploitation in next 30 days
58.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.