PT-2021-22778 · Gitlab · Gitlab Runner+1

Georgi N. Georgiev

·

Published

2021-12-13

·

Updated

2024-03-06

·

CVE-2021-39939

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab Runner versions 13.7 through 14.3.6 GitLab Runner versions 14.4 through 14.4.4 GitLab Runner versions 14.5 through 14.5.2
Description An uncontrolled resource consumption issue in GitLab Runner allows an attacker to trigger a job with a specially crafted docker image, potentially exhausting resources on the runner manager.
Recommendations For versions 13.7 through 14.3.6, update to version 14.3.6 or later. For versions 14.4 through 14.4.4, update to version 14.4.4 or later. For versions 14.5 through 14.5.2, update to version 14.5.2 or later.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39939
CVE-2021-39939

Affected Products

Gitlab
Gitlab Runner