PT-2022-4617 · Gitlab · Gitlab Ce/Ee+1

Published

2022-08-30

·

Updated

2025-05-13

·

CVE-2022-2592

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 15.1.6 GitLab CE/EE version 15.2 prior to 15.2.4 GitLab CE/EE version 15.3 prior to 15.3.2
Description The issue is related to insufficient input validation in GitLab, allowing a remote attacker to cause a denial of service. Specifically, a lack of length validation in Snippet descriptions enables an authenticated attacker to create a maliciously large Snippet. When this Snippet is requested, either with or without authentication, it places an excessive load on the server, potentially leading to a denial of service.
Recommendations For GitLab CE/EE versions prior to 15.1.6, update to version 15.1.6 or later. For GitLab CE/EE version 15.2 prior to 15.2.4, update to version 15.2.4 or later. For GitLab CE/EE version 15.3 prior to 15.3.2, update to version 15.3.2 or later.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-05495
BIT-GITLAB-2022-2592
CVE-2022-2592

Affected Products

Gitlab
Gitlab Ce/Ee