CVE-2022-2931: High severity gitlab vulnerability
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2931?
CVE-2022-2931 has a high severity rating due to its potential to cause denial of service (DoS) by consuming high CPU resources.
How do I fix CVE-2022-2931?
To fix CVE-2022-2931, you should upgrade your GitLab instance to version 15.1.6 or above, or to a secure version above 15.2.4 or 15.3.2.
Which versions of GitLab are affected by CVE-2022-2931?
CVE-2022-2931 affects all versions of GitLab before 15.1.6, as well as versions starting from 15.2 up to 15.2.4 and from 15.3 up to 15.3.2.
What can trigger the vulnerability described in CVE-2022-2931?
CVE-2022-2931 can be triggered by adding malformed content to the issue description in GitLab.
Is there a workaround for CVE-2022-2931?
There is no official workaround for CVE-2022-2931, and users are advised to upgrade to a patched version as soon as possible.