CVE-2022-3283Uncontrolled Resource Consumption in Gitlab

Severity
7.5HIGHNVD
EPSS
0.6%
top 30.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab15.315.3.4+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab<15.2.5, >=15.3, <15.3.4, >=15.4, <15.4.1+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2022-3283: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 152022-10-17
GHSA
GHSA-2q5x-gf4q-9227: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 152022-10-17

📋Vendor Advisories

2
GitLab
CVE-2022-3283: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.2022-10-17
Debian
CVE-2022-3283: gitlab - A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versi...2022