CVE-2022-3639: High severity gitlab vulnerability
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3639?
CVE-2022-3639 has a moderate severity level due to its potential to cause denial-of-service (DOS) conditions.
How do I fix CVE-2022-3639?
To fix CVE-2022-3639, you should upgrade your GitLab instance to version 15.1.6, 15.2.4 or 15.3.2 or higher.
What versions of GitLab are affected by CVE-2022-3639?
CVE-2022-3639 affects all GitLab versions from 10.8 before 15.1.6, from 15.2 before 15.2.4, and from 15.3 before 15.3.2.
What kind of vulnerability is CVE-2022-3639?
CVE-2022-3639 is a potential denial-of-service (DOS) vulnerability caused by improper data handling during branch creation.
What can an attacker achieve with CVE-2022-3639?
An attacker could exploit CVE-2022-3639 to trigger high CPU usage on the affected GitLab server, affecting its availability.