CVE-2022-1174: High severity gitlab vulnerability
A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1174?
CVE-2022-1174 is a potential Denial of Service (DoS) vulnerability in Gitlab CE/EE versions 13.7 before 14.7.7 and all versions starting from 14.8 before 14.8.5, and 14.9 before 14.9.2.
How can an attacker exploit CVE-2022-1174?
An attacker can trigger high CPU usage and potentially cause a Denial of Service (DoS) by sending a specially crafted input added in Issues, Merge requests, or Milestones in Gitlab.
What is the severity rating of CVE-2022-1174?
CVE-2022-1174 has a severity rating of "high" with a CVSS score of 7.5.
Which versions of Gitlab are affected by CVE-2022-1174?
CVE-2022-1174 affects Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, and all versions starting from 14.9 before 14.9.2.
How can I mitigate the vulnerability in Gitlab CVE-2022-1174?
To mitigate the vulnerability, it is recommended to upgrade Gitlab CE/EE to version 14.7.7, 14.8.5, or 14.9.2, depending on the affected version.