CVE-2022-1185Out-of-bounds Write in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 41.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateApr 12

Description

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

NVDgitlab/gitlab10.0.014.7.7+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=10.0, <14.7.7, >=14.8, <14.8.5, >=14.9, <14.9.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-q757-g3qv-54vf: A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 142022-04-05
OSV
CVE-2022-1185: A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 142022-04-04

📋Vendor Advisories

38
Microsoft
Chromium: CVE-2022-1313 Use after free in tab groups2022-04-12
Microsoft
Chromium: CVE-2022-1127 Use after free in QR Code Generator2022-04-12
Microsoft
Chromium: CVE-2022-1129 Inappropriate implementation in Full Screen Mode2022-04-12
Microsoft
Microsoft Edge (Chromium-based) Spoofing Vulnerability2022-04-12
Microsoft
Chromium: CVE-2022-1146 Inappropriate implementation in Resource Timing2022-04-12