MEDIUM
CVE-2020-13281
CVSS
6.5
Description
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
Summary dbcve.org
A denial of service vulnerability exists in GitLab's project import feature affecting versions prior to 13.0.12, 13.1.6, and 13.2.3. An attacker with project import permissions can exploit this to cause the service to become unavailable, likely through resource exhaustion or malformed import handling.
Mitigation
Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later. In the interim, restrict project import permissions to trusted users only and monitor for unusual import activity.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.33%
Probability of exploitation in next 30 days
69.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.