A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/289950 | broken link |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22168.json | vendor advisory |