MEDIUM
CVE-2022-3818
CVSS
5.3
Description
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.
Summary dbcve.org
GitLab CE/EE contains an uncontrolled resource consumption vulnerability in its URL parsing functionality. Attackers can craft malicious URLs that cause excessive resource consumption during parsing, leading to performance degradation and potential denial of service on the GitLab instance.
Mitigation
Upgrade GitLab to version 15.3.5, 15.4.4, or 15.5.2 or later to resolve the URL parsing resource consumption issue.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
0.71%
Probability of exploitation in next 30 days
52.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.