CVE-2022-1121: Medium severity gitlab vulnerability
Published Apr 4, 2022
·Updated
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.
Affected Software
6 affected components
GitLab GitLab<14.7.7
GitLab GitLab<14.7.7
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.8.0<14.8.5
GitLab GitLab>=14.9.0<14.9.2
GitLab GitLab>=14.9.0<14.9.2
Event History
Apr 4, 2022
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1121?
CVE-2022-1121 is considered a critical vulnerability due to the potential for unlimited resource consumption.
2
How do I fix CVE-2022-1121?
To fix CVE-2022-1121, upgrade to GitLab versions 14.7.7, 14.8.5, or 14.9.2 or later.
3
What systems are affected by CVE-2022-1121?
CVE-2022-1121 affects GitLab CE/EE versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2.
4
What type of attack does CVE-2022-1121 facilitate?
CVE-2022-1121 enables an attacker to launch Denial of Service (DoS) attacks through resource exhaustion.
5
Is CVE-2022-1121 present in all GitLab versions?
No, CVE-2022-1121 is only present in GitLab versions prior to the specified fixed versions.