HIGH

CVE-2019-13003

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

Summary dbcve.org

A parser used by GitLab CI prior to version 12.0.3 is vulnerable to resource exhaustion, allowing attackers to consume excessive server resources and cause denial of service through malformed CI pipeline configurations.

Mitigation

Upgrade GitLab Community or Enterprise Edition to version 12.0.3 or later to patch the vulnerable CI parser.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.44%
Probability of exploitation in next 30 days
72th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE