Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3613

Опубликовано: 12 янв. 2023
Источник: nvd
CVSS3: 5.8
CVSS3: 7.5
EPSS Низкий

Описание

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Версия до 15.5.7 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия до 15.5.7 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Версия от 15.6.0 (включая) до 15.6.4 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 15.6.0 (включая) до 15.6.4 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Версия от 15.7.0 (включая) до 15.7.2 (исключая)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Версия от 15.7.0 (включая) до 15.7.2 (исключая)

EPSS

Процентиль: 48%
0.00254
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-400

Связанные уязвимости

CVSS3: 5.8
ubuntu
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

CVSS3: 5.8
debian
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 7.5
github
около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

EPSS

Процентиль: 48%
0.00254
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-400