PT-2022-13659 · Gitlab · Gitlab Ce/Ee+1

Published

2022-04-04

·

Updated

2024-03-06

·

CVE-2022-1099

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 14.7.7 GitLab CE/EE versions 14.8 prior to 14.8.5 GitLab CE/EE versions 14.9 prior to 14.9.2
Description The issue allows an attacker to impact the performance of GitLab by adding a very large number of tags to a runner. This can be exploited to affect the system's performance.
Recommendations For versions prior to 14.7.7, update to version 14.7.7 or later. For versions 14.8 prior to 14.8.5, update to version 14.8.5 or later. For versions 14.9 prior to 14.9.2, update to version 14.9.2 or later.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-1099
CVE-2022-1099

Affected Products

Gitlab
Gitlab Ce/Ee