PT-2021-14908 · Gitlab · Gitlab Ce/Ee+1
Published
2021-04-02
·
Updated
2024-08-21
·
CVE-2021-22197
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
GitLab CE/EE versions 10.6 and later
Description:
An issue exists where an infinite loop occurs when an authenticated user with specific rights accesses a merge request (MR) having source and target branches pointing to each other.
Recommendations:
For GitLab CE/EE versions 10.6 and later, consider restricting access to merge requests with circular branch references until a patch is available.
As a temporary workaround, limit the rights of authenticated users to prevent them from accessing such merge requests.
Avoid creating merge requests with source and target branches pointing to each other to minimize the risk of exploitation.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee