CVE-2022-0489: Medium severity gitlab vulnerability
Published Apr 1, 2022
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.
Affected Software
6 affected components
GitLab GitLab>=8.15.0<14.6.5
GitLab GitLab>=8.15.0<14.6.5
GitLab GitLab>=14.7.0<=14.7.4
GitLab GitLab>=14.7.0<=14.7.4
GitLab GitLab>=14.8.0<14.8.2
GitLab GitLab>=14.8.0<14.8.2
Remediation
Patch Available
Event History
Apr 1, 2022
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0489?
CVE-2022-0489 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2022-0489?
To remediate CVE-2022-0489, upgrade to GitLab version 14.6.5 or later.
3
Which versions of GitLab are affected by CVE-2022-0489?
CVE-2022-0489 affects all GitLab CE/EE versions starting from 8.15 up to 14.6.5.
4
What specific feature of GitLab is exploited in CVE-2022-0489?
The vulnerability is triggered by using the math feature with a specific formula in issue comments.
5
Can CVE-2022-0489 be exploited remotely?
Yes, CVE-2022-0489 can be exploited remotely by any user who can comment on issues.