PT-2022-13202 · Gitlab · Gitlab

Published

2022-04-25

·

Updated

2024-03-06

·

CVE-2022-0477

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab versions 11.9 through 14.5.3 GitLab versions 14.6.0 through 14.6.3 GitLab versions 14.7.0
Description An issue has been discovered in GitLab where it was not correctly handling bulk requests to delete existing packages from the package registries. This could result in a Denial of Service under specific conditions.
Recommendations For GitLab versions 11.9 through 14.5.3, update to version 14.5.4 or later. For GitLab versions 14.6.0 through 14.6.3, update to version 14.6.4 or later. For GitLab version 14.7.0, update to version 14.7.1 or later.

Exploit

Fix

Related Identifiers

BIT-GITLAB-2022-0477
CVE-2022-0477

Affected Products

Gitlab