6.5
CVSSv3

CVE-2022-3411

Published: 13/02/2023 Updated: 08/08/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 prior to 15.6.7, 15.7 prior to 15.7.6, and 15.8 prior to 15.8.1 allows an authenticated malicious user to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab