CVE-2022-3639 Information
Oct 22, 2022
cve
Description
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6 all versions starting from 15.2 before 15.2.4 all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://gitlab.com/gitlab-org/gitlab/-/issues/366876 https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3639.json
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: