HIGH
CVE-2019-13003
CVSS
7.5
Description
An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.
Summary dbcve.org
A parser used by GitLab CI prior to version 12.0.3 is vulnerable to resource exhaustion, allowing attackers to consume excessive server resources and cause denial of service through malformed CI pipeline configurations.
Mitigation
Upgrade GitLab Community or Enterprise Edition to version 12.0.3 or later to patch the vulnerable CI parser.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.44%
Probability of exploitation in next 30 days
72th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.