CVE-2022-1428

MEDIUM

GitLab < 14.8.6, 14.9 < 14.9.4, 14.10 < 14.10.1 - Allocation of Resources Without Limits or Throttling

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 33.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-770
Status published
Products (2)
gitlab/gitlab 14.10.0 (2 CPE variants)
gitlab/gitlab < 14.8.6 (2 CPE variants)
Published May 11, 2022
Tracked Since Feb 18, 2026