CVE-2022-1099: Medium severity gitlab vulnerability
Published Apr 4, 2022
·Updated
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab
Affected Software
6 affected components
GitLab GitLab<14.7.7
GitLab GitLab<14.7.7
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.9.0<14.9.2
GitLab GitLab>=14.9.0<14.9.2
Event History
Apr 4, 2022
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1099?
CVE-2022-1099 has been rated as a high severity vulnerability due to its impact on performance in GitLab.
2
Which versions of GitLab are affected by CVE-2022-1099?
CVE-2022-1099 affects all versions of GitLab prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2.
3
How do I fix CVE-2022-1099?
To fix CVE-2022-1099, upgrade your GitLab installation to version 14.7.7, 14.8.5, or 14.9.2 or later.
4
What type of vulnerability is CVE-2022-1099?
CVE-2022-1099 is a performance-related vulnerability allowing an attacker to degrade GitLab's performance.
5
What potential impact does CVE-2022-1099 have on GitLab?
CVE-2022-1099 can significantly impact the performance of GitLab, potentially leading to service disruptions.