CVE-2022-2931
HIGHGitLab < 15.1.6, 15.2-15.2.4, 15.3-15.3.2 - Denial of Service via Malformed Issue Description
Title source: llmDescription
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.
References (3)
Core 3
Core References
Third Party Advisory
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2931.json
Third Party Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/361982
Permissions Required, Third Party Advisory
https://hackerone.com/reports/1543718
Scores
CVSS v3
7.5
EPSS
0.0023
EPSS Percentile
45.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (1)
gitlab/gitlab
< 15.1.6 (2 CPE variants)
Published
Oct 17, 2022
Tracked Since
Feb 18, 2026