Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.
Solution:
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/417896 | issue tracking broken link |
https://hackerone.com/reports/2055158 | broken link exploit permissions required technical description |