MEDIUM

CVE-2022-3818

Gitlab GitLab 2022-11-10 CVSS v3.1
CVSS
5.3

Description

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

Summary dbcve.org

GitLab CE/EE contains an uncontrolled resource consumption vulnerability in its URL parsing functionality. Attackers can craft malicious URLs that cause excessive resource consumption during parsing, leading to performance degradation and potential denial of service on the GitLab instance.

Mitigation

Upgrade GitLab to version 15.3.5, 15.4.4, or 15.5.2 or later to resolve the URL parsing resource consumption issue.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.71%
Probability of exploitation in next 30 days
52.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE