MEDIUM

CVE-2019-13004

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
5.3

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).

Summary dbcve.org

In GitLab versions 11.10 through 12.0.2, the comment rendering functionality contains an incorrect access control issue where specific encoded characters injected into comments cause the entire comments section to become inaccessible to users. This appears to be a denial-of-service condition triggered by improper handling of encoded input.

Mitigation

Upgrade GitLab to version 12.0.3 or later. As a workaround, avoid posting comments containing the specific encoded character sequences that trigger this issue until patching is possible.

EPSS Score

1.11%
Probability of exploitation in next 30 days
64.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE