CVE-2022-2592: Medium severity gitlab vulnerability
A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2592?
CVE-2022-2592 is classified as a medium severity vulnerability due to its potential for denial of service.
How do I fix CVE-2022-2592?
To fix CVE-2022-2592, upgrade GitLab to version 15.1.6, 15.2.4, or 15.3.2 or later.
Who is affected by CVE-2022-2592?
CVE-2022-2592 affects all versions of GitLab Community and Enterprise Editions prior to the specified patched versions.
What kind of attack is possible with CVE-2022-2592?
An authenticated attacker can exploit CVE-2022-2592 by creating a maliciously large Snippet, causing excessive load on the server.
What components of GitLab are vulnerable in CVE-2022-2592?
The vulnerability in CVE-2022-2592 specifically impacts Snippet descriptions in GitLab.