CVE-2022-2931Uncontrolled Resource Consumption in Gitlab

Severity
7.5HIGHNVD
EPSS
0.3%
top 45.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab15.215.2.4+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab <15.1.6, >=15.2, <15.2.4, >=15.3, <15.3.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-p95h-29v8-j2h6: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 152022-10-17
OSV
CVE-2022-2931: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 152022-10-17

📋Vendor Advisories

2
GitLab
CVE-2022-2931: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all2022-10-17
Debian
CVE-2022-2931: gitlab - A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versi...2022