PT-2022-13660 · Gitlab · Gitlab Ce/Ee+1

Published

2022-04-04

·

Updated

2024-03-06

·

CVE-2022-1100

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.1 through 14.7.7 GitLab CE/EE versions 14.8.0 through 14.8.5 GitLab CE/EE versions 14.9.0 through 14.9.2
Description A potential DOS issue was discovered in GitLab CE/EE. The API to update an asset as a link from a release had a regex check which caused an exponential number of backtracks for certain user-supplied values, resulting in high CPU usage.
Recommendations For versions 13.1 through 14.7.7, update to version 14.7.7 or later. For versions 14.8.0 through 14.8.5, update to version 14.8.5 or later. For versions 14.9.0 through 14.9.2, update to version 14.9.2 or later.

Exploit

Fix

DoS

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-1100
CVE-2022-1100

Affected Products

Gitlab
Gitlab Ce/Ee