HIGH
CVE-2020-10089
CVSS
7.5
Description
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
Summary dbcve.org
GitLab versions 8.11 through 12.8.1 contain a denial-of-service vulnerability where multiple features can recursively request each other, creating an infinite loop or resource exhaustion condition that renders the service unavailable.
Mitigation
Upgrade GitLab to version 12.8.2 or later to resolve the recursive request DoS vulnerability; implement request rate limiting and circuit breakers as a compensating control if immediate upgrade is not feasible.
Weakness (CWE)
CWE-674
EPSS Score
1.15%
Probability of exploitation in next 30 days
65.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.