A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/376247 | broken link |
https://hackerone.com/reports/1685995 | permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3411.json | third party advisory |