CVE-2022-3639Uncontrolled Resource Consumption in Gitlab

Severity
7.5HIGHNVD
EPSS
0.2%
top 58.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab10.8.015.1.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=10.8, <15.1.6, >=15.2, <15.2.4, >=15.3, <15.3.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2022-3639: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 102022-10-21
GHSA
GHSA-fmg9-cqhf-254r: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 102022-10-21

📋Vendor Advisories

2
GitLab
CVE-2022-3639: A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 152022-10-21
Debian
CVE-2022-3639: gitlab - A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versi...2022