CVE-2022-1185

MEDIUM

GitLab 10.0.0-14.7.7 14.8.0-14.8.5 14.9.0-14.9.2 - Denial of Service via RDoc File Rendering

Title source: llm
STIX 2.1

Description

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1415071

Scores

CVSS v3 6.5
EPSS 0.0037
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (1)
gitlab/gitlab 10.0.0 - 14.7.7 (2 CPE variants)
Published Apr 04, 2022
Tracked Since Feb 18, 2026