CVE-2022-3283

HIGH

GitLab CE/EE <15.2.5, <15.3.4, <15.4.1 - DoS

Title source: llm
STIX 2.1

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

References (3)

Core 3
Core References
Exploit, Issue Tracking, Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/361982
Permissions Required, Third Party Advisory
https://hackerone.com/reports/1543718

Scores

CVSS v3 7.5
EPSS 0.0044
EPSS Percentile 63.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (1)
gitlab/gitlab < 15.2.5 (2 CPE variants)
Published Oct 17, 2022
Tracked Since Feb 18, 2026