CVE-2022-0488

LOW

GitLab CE/EE <8.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

References (2)

Core 2
Core References
Broken Link, Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab/-/issues/23520

Scores

CVSS v3 3.5
EPSS 0.0014
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

Details

CWE
CWE-400
Status published
Products (1)
gitlab/gitlab 8.10 - 14.5.4 (2 CPE variants)
Published Mar 28, 2022
Tracked Since Feb 18, 2026