7.5

CVE-2022-1510

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 13.9.0 < 14.8.6
Gitlab ≫ GitLab SwEdition enterprise Version >= 13.9.0 < 14.8.6
Gitlab ≫ GitLab SwEdition community Version >= 14.9.0 < 14.9.4
Gitlab ≫ GitLab SwEdition enterprise Version >= 14.9.0 < 14.9.4
Gitlab ≫ GitLab Version 14.10.0 SwEdition community
Gitlab ≫ GitLab Version 14.10.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.89% 0.774
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
cve@gitlab.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1510.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/343276
Broken Link
https://hackerone.com/reports/1353058
Third Party Advisory
Permissions Required