MEDIUM

CVE-2020-26409

Gitlab GitLab 2020-12-11 CVSS v3.1
CVSS
6.5

Description

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

Summary dbcve.org

A denial of service vulnerability exists in GitLab CE/EE's markdown processing where input validation can be bypassed, allowing attackers to submit specially crafted markdown content that triggers uncontrolled resource consumption.

Mitigation

Upgrade GitLab to version 13.4.7, 13.5.5, or 13.6.2 (or later) to patch the vulnerability in the markdown field validation.

Weakness (CWE)

CWE-20 Improper Input Validation
CWE-400 Uncontrolled Resource Consumption

EPSS Score

1.26%
Probability of exploitation in next 30 days
68.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE