CVE-2022-2908: Medium severity gitlab vulnerability
A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2908?
CVE-2022-2908 is classified as a denial of service (DoS) vulnerability, which can lead to high CPU usage.
How do I fix CVE-2022-2908?
To mitigate CVE-2022-2908, update GitLab to version 15.1.5 or later, 15.2.3 or later, or 15.3.1 or later.
Which versions of GitLab are affected by CVE-2022-2908?
CVE-2022-2908 affects GitLab CE/EE versions starting from 10.7 up to 15.3 before 15.3.1.
What causes the CVE-2022-2908 vulnerability?
CVE-2022-2908 is caused by a specially crafted input in the commit message that can trigger excessive CPU usage.
Is CVE-2022-2908 exploitable remotely?
Yes, CVE-2022-2908 can be exploited remotely by sending a specially crafted commit message.