HIGH

CVE-2020-13274

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
7.5

Description

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

Summary dbcve.org

GitLab versions through 13.0.1 are vulnerable to a denial of service attack via memory exhaustion through malicious artifact uploads. The artifact upload functionality lacks proper bounds checking, allowing attackers to consume excessive memory and crash the service.

Mitigation

Upgrade GitLab to version 13.0.2 or later to patch the vulnerability. If immediate upgrade is not possible, consider restricting or temporarily disabling artifact uploads.

EPSS Score

1.15%
Probability of exploitation in next 30 days
65.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE