HIGH

CVE-2022-3639

Gitlab GitLab 2022-10-21 CVSS v3.1
CVSS
7.5

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

Summary dbcve.org

A denial-of-service vulnerability in GitLab CE/EE allows attackers to trigger high CPU usage via improper data handling during branch creation, causing service degradation or unavailability.

Mitigation

Upgrade GitLab to version 15.1.6, 15.2.4, 15.3.2, or later to resolve the improper data handling in branch creation that causes excessive CPU consumption.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.9%
Probability of exploitation in next 30 days
58.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE