HIGH
CVE-2020-13274
CVSS
7.5
Description
A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1
Summary dbcve.org
GitLab versions through 13.0.1 are vulnerable to a denial of service attack via memory exhaustion through malicious artifact uploads. The artifact upload functionality lacks proper bounds checking, allowing attackers to consume excessive memory and crash the service.
Mitigation
Upgrade GitLab to version 13.0.2 or later to patch the vulnerability. If immediate upgrade is not possible, consider restricting or temporarily disabling artifact uploads.
EPSS Score
1.15%
Probability of exploitation in next 30 days
65.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.