First published: Fri Jun 11 2021(Updated: )
A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.8.0<13.10.5 | |
GitLab | >=11.8.0<13.10.5 | |
GitLab | >=13.11.0<13.11.5 | |
GitLab | >=13.11.0<13.11.5 | |
GitLab | >=13.12.0<13.12.2 | |
GitLab | >=13.12.0<13.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22181 is categorized as a denial of service vulnerability affecting all versions of GitLab since 11.8.
To mitigate CVE-2021-22181, it is recommended to upgrade GitLab to versions 13.10.6, 13.11.6, or 13.12.3 or later.
CVE-2021-22181 affects all versions of GitLab CE/EE from 11.8.0 to 13.10.5, 13.11.0 to 13.11.5, and 13.12.0 to 13.12.2.
CVE-2021-22181 allows an attacker to create recursive pipeline relationships, leading to resource exhaustion.
Currently, there are no specific workarounds for CVE-2021-22181; upgrading to a fixed version is the recommended action.