PT-2021-14908 · Gitlab · Gitlab Ce/Ee+1

Published

2021-04-02

·

Updated

2024-08-21

·

CVE-2021-22197

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 10.6 and later
Description: An issue exists where an infinite loop occurs when an authenticated user with specific rights accesses a merge request (MR) having source and target branches pointing to each other.
Recommendations: For GitLab CE/EE versions 10.6 and later, consider restricting access to merge requests with circular branch references until a patch is available. As a temporary workaround, limit the rights of authenticated users to prevent them from accessing such merge requests. Avoid creating merge requests with source and target branches pointing to each other to minimize the risk of exploitation.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-22197
CVE-2021-22197

Affected Products

Gitlab
Gitlab Ce/Ee