HIGH
CVE-2020-13273
CVSS
7.5
Description
A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
Summary dbcve.org
Denial of Service vulnerability in GitLab CE/EE versions 12.0 through 13.0.1 allows attackers to exhaust system resources, likely through malformed requests or API abuse that consumes excessive CPU, memory, or disk I/O.
Mitigation
Upgrade GitLab to version 13.0.2 or later. Implement rate limiting and resource quotas as an interim control if immediate upgrade is not feasible.
EPSS Score
1.19%
Probability of exploitation in next 30 days
66.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.