HIGH
CVE-2020-10073
CVSS
7.5
Description
GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.
Summary dbcve.org
GitLab EE versions 12.4.2 through 12.8.1 contain a denial of service vulnerability in the permissions check logic that affects project home page rendering, allowing attackers to potentially cause service unavailability through specially crafted requests.
Mitigation
Upgrade GitLab EE to version 12.8.2 or later to patch the denial of service vulnerability in the permissions check functionality.
EPSS Score
1.12%
Probability of exploitation in next 30 days
64.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.