PT-2022-12996 · Gitlab · Gitlab

Published

2022-01-18

·

Updated

2024-03-06

·

CVE-2022-0151

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab versions 12.10 through 14.4.5 GitLab versions 14.5.0 through 14.5.3 GitLab versions 14.6.0 through 14.6.2
Description An issue has been discovered in GitLab where it was not correctly handling requests to delete existing packages, which could result in a Denial of Service under specific conditions.
Recommendations For versions 12.10 through 14.4.5, update to version 14.4.5 or later to resolve the issue. For versions 14.5.0 through 14.5.3, update to version 14.5.3 or later to resolve the issue. For versions 14.6.0 through 14.6.2, update to version 14.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to package deletion requests until a patch is available.

Exploit

Fix

Related Identifiers

BIT-GITLAB-2022-0151
CVE-2022-0151

Affected Products

Gitlab