HIGH

CVE-2020-13315

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
7.5

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.

Summary dbcve.org

The profile activity page in GitLab versions prior to 13.1.10, 13.2.8, and 13.3.4 lacked proper result limiting, allowing users to request unbounded query results. This unrestricted resource consumption could be exploited to cause denial of service through excessive database or server resource usage.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. Alternatively, implement rate limiting on the profile activity endpoint as a compensating control until upgrade is possible.

EPSS Score

2.08%
Probability of exploitation in next 30 days
80.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE