CVE-2022-1510

MEDIUM

GitLab <14.8.6-14.9.4-14.10.1 - DoS

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1333
Status published
Products (2)
gitlab/gitlab 14.10.0 (2 CPE variants)
gitlab/gitlab 13.9.0 - 14.8.6 (2 CPE variants)
Published May 11, 2022
Tracked Since Feb 18, 2026