CVE-2022-3639

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
21/10/2022
Last modified:
07/05/2025

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* 10.8.0 (including) 15.1.6 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* 15.2 (including) 15.2.4 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* 15.3 (including) 15.3.2 (excluding)