CVE-2021-39912: Medium severity gitlab vulnerability
Published Nov 4, 2021
·Updated
A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.
Affected Software
6 affected components
GitLab GitLab>=13.7.0<14.2.6
GitLab GitLab>=13.7.0<14.2.6
GitLab GitLab>=14.3.0<14.3.4
GitLab GitLab>=14.3.0<14.3.4
GitLab GitLab>=14.4.0<14.4.1
GitLab GitLab>=14.4.0<14.4.1
Event History
Nov 4, 2021
CVE Published
via MITRE·11:05 PM
Data Sourced
via MITRE·11:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-39912?
CVE-2021-39912 is considered a high severity DoS vulnerability in GitLab CE/EE.
2
How do I fix CVE-2021-39912?
To fix CVE-2021-39912, upgrade GitLab to version 14.2.6 or later for versions between 13.7.0 and 14.2.6.
3
What versions are affected by CVE-2021-39912?
CVE-2021-39912 affects GitLab CE/EE versions from 13.7.0 to 14.2.6, including some versions in the 14.3.x and 14.4.x range.
4
How can CVE-2021-39912 be exploited?
CVE-2021-39912 can be exploited by sending a malformed TIFF image to trigger memory exhaustion.
5
What should I do if I'm using vulnerable versions of GitLab related to CVE-2021-39912?
If you're using vulnerable versions, you should upgrade immediately to a patched version to mitigate the risk.