CVE-2022-0477

MEDIUM

GitLab <14.5.4, <14.6.4, <14.7.1 - DoS

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

References (2)

Core 2

Scores

CVSS v3 4.9
EPSS 0.0019
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (2)
gitlab/gitlab 14.7.0
gitlab/gitlab 11.9 - 14.5.4
Published Apr 25, 2022
Tracked Since Feb 18, 2026