GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 17.2, < 18.2.7
- >= 18.3, < 18.3.3
- >= 18.4, < 18.4.1
A denial-of-service vulnerability has been identified in GitLab CE/EE versions 17.2 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1. This vulnerability allows an attacker to cause uncontrolled CPU usage, potentially leading to a denial-of-service condition, by using specific GraphQL queries.
Exploitation of this vulnerability can cause excessive CPU consumption, leading to degraded performance or unavailability of the GitLab instance.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.