MEDIUM

CVE-2020-13281

Gitlab GitLab 2020-08-13 CVSS v3.1
CVSS
6.5

Description

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

Summary dbcve.org

A denial of service vulnerability exists in GitLab's project import feature affecting versions prior to 13.0.12, 13.1.6, and 13.2.3. An attacker with project import permissions can exploit this to cause the service to become unavailable, likely through resource exhaustion or malformed import handling.

Mitigation

Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later. In the interim, restrict project import permissions to trusted users only and monitor for unusual import activity.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.33%
Probability of exploitation in next 30 days
69.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE