CVE-2021-22168: Medium severity gitlab vulnerability
Published Jan 15, 2021
·Updated
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
Affected Software
6 affected components
GitLab GitLab>=12.8.0<13.5.6
GitLab GitLab>=12.8.0<13.5.6
GitLab GitLab>=13.6.0<13.6.4
GitLab GitLab>=13.6.0<13.6.4
GitLab GitLab>=13.7.0<13.7.2
GitLab GitLab>=13.7.0<13.7.2
Event History
Jan 15, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22168?
CVE-2021-22168 has been classified as a denial of service vulnerability with medium severity.
2
How do I fix CVE-2021-22168?
To mitigate CVE-2021-22168, upgrade GitLab to version 13.5.7 or later for supported versions.
3
Which versions of GitLab are affected by CVE-2021-22168?
CVE-2021-22168 affects all versions of GitLab from 12.8.0 to 13.7.2, except those that have been patched.
4
What kind of attack is possible with CVE-2021-22168?
CVE-2021-22168 allows attackers to exploit a regular expression denial of service, potentially overwhelming the service.
5
Is there a workaround for CVE-2021-22168?
There are no documented workarounds for CVE-2021-22168; the recommended action is to upgrade to a secure version.