Uncontrolled Resource Consumption Vulnerability in GitLab Runner
CVE-2021-39939
6.5MEDIUM
Summary
A vulnerability exists in GitLab Runner that allows attackers to consume excessive resources on the runner manager. This issue affects all versions from 13.7 up to, but not including, 14.3.6, as well as versions 14.4 up to 14.4.4, and 14.5 up to 14.5.2. An attacker can exploit this vulnerability by triggering a job with a specially crafted docker image, resulting in resource exhaustion that may lead to service interruption.
Affected Version(s)
GitLab Runner >=13.7, <14.3.6 < 13.7, 14.3.6
GitLab Runner >=14.4, <14.4.4 < 14.4, 14.4.4
GitLab Runner >=14.5, <14.5.2 < 14.5, 14.5.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by the GitLab team