PT-2022-13881 · Gitlab · Gitlab
David Fernandez
·
Published
2022-05-11
·
Updated
2024-03-06
·
CVE-2022-1428
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab versions prior to 14.8.6
GitLab versions 14.9 through 14.9.4
GitLab versions 14.10 through 14.10.1
Description
The issue in GitLab arises from incorrect verification of throttling limits for authenticated package requests, resulting in these limits not being enforced.
Recommendations
For versions prior to 14.8.6, update to version 14.8.6 or later.
For versions 14.9 through 14.9.3, update to version 14.9.4 or later.
For versions 14.10 through 14.10.0, update to version 14.10.1 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab