CVE-2022-1099

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
04/04/2022
Last modified:
11/04/2022

Description

Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 14.7.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.7.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 14.8.0 (including) 14.8.5 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.8.0 (including) 14.8.5 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 14.9.0 (including) 14.9.2 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.9.0 (including) 14.9.2 (excluding)