CVE-2022-0151

MEDIUM

GitLab 12.10-14.4.4, 14.5.0-14.5.2, 14.6.0-14.6.1 - Denial of Service via Package Deletion Request

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0111
EPSS Percentile 61.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Details

Status published
Products (1)
gitlab/gitlab 12.10 - 14.4.5 (2 CPE variants)
Published Jan 18, 2022
Tracked Since Feb 18, 2026