HIGH

CVE-2020-10954

Gitlab GitLab 2020-03-27 CVSS v3.1
CVSS
7.5

Description

GitLab through 12.9 is affected by a potential DoS in repository archive download.

Summary dbcve.org

GitLab versions through 12.9 contain a denial-of-service vulnerability in the repository archive download functionality. The vulnerability allows attackers to potentially crash or make the archive download feature unavailable, likely through resource exhaustion or malformed input processing.

Mitigation

Upgrade GitLab to version 12.9.1 or later (or the latest stable version). If immediate patching is not possible, consider rate-limiting archive download endpoints and monitoring for anomalous download patterns.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.15%
Probability of exploitation in next 30 days
65.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE