HIGH

CVE-2020-13325

Gitlab GitLab 2020-09-30 CVSS v3.1
CVSS
7.1

Description

A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.

Summary dbcve.org

In GitLab versions prior to 13.1, the comment input field on issue pages lacked proper character validation, allowing specially crafted input to trigger a denial of service condition. This is an input validation failure that permits malformed or excessive characters to cause the application to become unresponsive or crash.

Mitigation

Upgrade GitLab to version 13.1 or later, which implements proper character restrictions on the issue comment field to prevent denial of service attacks.

EPSS Score

0.93%
Probability of exploitation in next 30 days
58.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE