CVE-2021-22166: High severity gitlab vulnerability
Published Jan 15, 2021
·Updated
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
Affected Software
2 affected components
GitLab GitLab>=13.7.0<13.7.2
GitLab GitLab>=13.7.0<13.7.2
Event History
Jan 15, 2021
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22166?
CVE-2021-22166 has a severity rating that can impact the availability of GitLab due to the potential for denial of service.
2
How do I fix CVE-2021-22166?
To fix CVE-2021-22166, users should upgrade to GitLab version 13.7.2 or later.
3
What software versions are affected by CVE-2021-22166?
CVE-2021-22166 affects GitLab versions 13.7.0 to 13.7.2 inclusive for both community and enterprise editions.
4
What type of attack is associated with CVE-2021-22166?
CVE-2021-22166 is associated with a denial of service attack triggered by sending a malformed HTTP request.
5
Is CVE-2021-22166 present in versions after 13.7.2 of GitLab?
CVE-2021-22166 should not be present in versions beyond 13.7.2 as it was resolved in later updates.