First published: Tue Jan 18 2022(Updated: )
A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab GitLab | >=12.0<14.3.6 | |
GitLab GitLab | >=12.0<14.3.6 | |
GitLab GitLab | >=14.4<14.4.4 | |
GitLab GitLab | >=14.4<14.4.4 | |
GitLab GitLab | >=14.5<14.5.2 | |
GitLab GitLab | >=14.5<14.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.