HIGH
CVE-2020-10954
CVSS
7.5
Description
GitLab through 12.9 is affected by a potential DoS in repository archive download.
Summary dbcve.org
GitLab versions through 12.9 contain a denial-of-service vulnerability in the repository archive download functionality. The vulnerability allows attackers to potentially crash or make the archive download feature unavailable, likely through resource exhaustion or malformed input processing.
Mitigation
Upgrade GitLab to version 12.9.1 or later (or the latest stable version). If immediate patching is not possible, consider rate-limiting archive download endpoints and monitoring for anomalous download patterns.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.15%
Probability of exploitation in next 30 days
65.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.