First published: Fri Jan 15 2021(Updated: )
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.7.0<13.7.2 | |
GitLab | >=13.7.0<13.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22166 has a severity rating that can impact the availability of GitLab due to the potential for denial of service.
To fix CVE-2021-22166, users should upgrade to GitLab version 13.7.2 or later.
CVE-2021-22166 affects GitLab versions 13.7.0 to 13.7.2 inclusive for both community and enterprise editions.
CVE-2021-22166 is associated with a denial of service attack triggered by sending a malformed HTTP request.
CVE-2021-22166 should not be present in versions beyond 13.7.2 as it was resolved in later updates.