HIGH

CVE-2020-13306

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
7.5

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.

Summary dbcve.org

GitLab versions before 13.1.10, 13.2.8, and 13.3.4 contain a vulnerability in the Webhook feature where rate limiting was not implemented. This allowed attackers to flood webhooks with requests, leading to denial of service conditions against the GitLab instance or downstream systems.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. If immediate upgrade is not possible, implement upstream rate limiting or firewall rules to restrict webhook request rates.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

1.83%
Probability of exploitation in next 30 days
77.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE