Severity
6.5MEDIUMNVD
EPSS
2.7%
top 14.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateOct 21

Description

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab12.415.6.7+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=12.4, <15.6.7, >=15.7, <15.7.6, >=15.8, <15.8.1+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-w4fh-mw73-5c5w: A lack of length validation in GitLab CE/EE affecting all versions from 122023-02-14
OSV
CVE-2022-3411: A lack of length validation in GitLab CE/EE affecting all versions from 122023-02-13

📋Vendor Advisories

3
Red Hat
kernel: gpiolib: fix memory leak in gpiochip_setup_dev()2024-10-21
GitLab
CVE-2022-3411: A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authe2023-02-13
Debian
CVE-2022-3411: gitlab - A lack of length validation in GitLab CE/EE affecting all versions from 12.4 bef...2022

📄Research Papers

1
arXiv
ICAR, a categorical framework to connect vulnerability, threat and asset managements2023-06-21