PT-2021-4084 · Gitlab · Gitlab Ce/Ee+1

Published

2021-01-05

·

Updated

2024-03-06

·

CVE-2021-22216

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 13.10.5 GitLab CE/EE versions prior to 13.11.5 GitLab CE/EE versions prior to 13.12.2
Description The issue is related to uncontrolled resource consumption, which can be exploited by an attacker to cause a denial of service. This can be achieved by using a very long issue or merge request description.
Recommendations For versions prior to 13.10.5, update to version 13.10.5 or later to resolve the issue. For versions prior to 13.11.5, update to version 13.11.5 or later to resolve the issue. For versions prior to 13.12.2, update to version 13.12.2 or later to resolve the issue. As a temporary workaround, consider restricting the length of issue or merge request descriptions to prevent uncontrolled resource consumption.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2021-04662
BIT-GITLAB-2021-22216
CVE-2021-22216

Affected Products

Gitlab
Gitlab Ce/Ee