CVE-2022-1431: Input Validation
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1431?
The severity of CVE-2022-1431 is classified as critical due to its impact on the security of the GitLab instance.
How do I fix CVE-2022-1431?
To fix CVE-2022-1431, you should upgrade your GitLab instance to version 14.8.6 or later, or to 14.9.4 or later if on the 14.9 series.
What versions of GitLab are affected by CVE-2022-1431?
CVE-2022-1431 affects all GitLab versions from 12.10 to before 14.8.6, from 14.9 to before 14.9.4, and from 14.10 to before 14.10.1.
Can CVE-2022-1431 be exploited remotely?
Yes, CVE-2022-1431 can be exploited remotely by sending malicious requests to the PyPi API endpoint.
What should I do if I cannot immediately update due to CVE-2022-1431?
If you cannot update immediately due to CVE-2022-1431, consider implementing network segmentation or rate limiting to mitigate potential exploitation.