CVE-2019-13004
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).
Summary dbcve.org
In GitLab versions 11.10 through 12.0.2, the comment rendering functionality contains an incorrect access control issue where specific encoded characters injected into comments cause the entire comments section to become inaccessible to users. This appears to be a denial-of-service condition triggered by improper handling of encoded input.
Mitigation
Upgrade GitLab to version 12.0.3 or later. As a workaround, avoid posting comments containing the specific encoded character sequences that trigger this issue until patching is possible.