PT-2021-22777 · Gitlab · Gitlab Ce/Ee+1

Dominic Couture

·

Published

2021-12-13

·

Updated

2024-03-06

·

CVE-2021-39938

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.15 through 14.3.6 GitLab CE/EE versions 14.4 through 14.4.4 GitLab CE/EE versions 14.5 through 14.5.2
Description A vulnerable regular expression pattern in GitLab CE/EE allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands.
Recommendations For versions 8.15 through 14.3.6, update to version 14.3.6 or later to resolve the issue. For versions 14.4 through 14.4.4, update to version 14.4.4 or later to resolve the issue. For versions 14.5 through 14.5.2, update to version 14.5.2 or later to resolve the issue.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39938
CVE-2021-39938

Affected Products

Gitlab
Gitlab Ce/Ee