HIGH

CVE-2020-13273

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
7.5

Description

A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

Summary dbcve.org

Denial of Service vulnerability in GitLab CE/EE versions 12.0 through 13.0.1 allows attackers to exhaust system resources, likely through malformed requests or API abuse that consumes excessive CPU, memory, or disk I/O.

Mitigation

Upgrade GitLab to version 13.0.2 or later. Implement rate limiting and resource quotas as an interim control if immediate upgrade is not feasible.

EPSS Score

1.19%
Probability of exploitation in next 30 days
66.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE