HIGH

CVE-2020-10089

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
7.5

Description

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

Summary dbcve.org

GitLab versions 8.11 through 12.8.1 contain a denial-of-service vulnerability where multiple features can recursively request each other, creating an infinite loop or resource exhaustion condition that renders the service unavailable.

Mitigation

Upgrade GitLab to version 12.8.2 or later to resolve the recursive request DoS vulnerability; implement request rate limiting and circuit breakers as a compensating control if immediate upgrade is not feasible.

Weakness (CWE)

CWE-674

EPSS Score

1.15%
Probability of exploitation in next 30 days
65.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE