MEDIUM

CVE-2019-13010

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
5.9

Description

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

Summary dbcve.org

The color codes decoder in GitLab Enterprise Edition 8.3 through 12.0.2 is vulnerable to uncontrolled resource consumption. Attackers can send specially crafted color code formats that cause excessive resource depletion, leading to denial of service.

Mitigation

Upgrade GitLab Enterprise Edition to version 12.0.3 or later. If immediate patching is not possible, consider rate limiting or input validation on color code processing endpoints as a temporary mitigation.

EPSS Score

0.94%
Probability of exploitation in next 30 days
59.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE