CVE-2021-22177: Medium severity gitlab vulnerability
Published Apr 1, 2021
·Updated
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.
Affected Software
6 affected components
GitLab GitLab>=12.6.0<13.6.7
GitLab GitLab>=12.6.0<13.6.7
GitLab GitLab>=13.7.0<13.7.7
GitLab GitLab>=13.7.0<13.7.7
GitLab GitLab>=13.8.0<13.8.4
GitLab GitLab>=13.8.0<13.8.4
Event History
Apr 1, 2021
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22177?
CVE-2021-22177 has a severity rating that indicates a potential denial of service vulnerability.
2
How do I fix CVE-2021-22177?
To fix CVE-2021-22177, upgrade GitLab CE/EE to the latest version that addresses this vulnerability.
3
What versions are affected by CVE-2021-22177?
CVE-2021-22177 affects GitLab CE/EE versions from 12.6.0 up to and including 13.8.4.
4
What kind of attack does CVE-2021-22177 allow?
CVE-2021-22177 allows an attacker to spike server resource utilization, potentially leading to service disruption.
5
Is CVE-2021-22177 a remote or local vulnerability?
CVE-2021-22177 is considered a remote vulnerability as it can be exploited by an attacker without physical access to the system.