PT-2020-13415 · Gitlab · Gitlab

Published

2020-06-19

·

Updated

2024-03-06

·

CVE-2020-13274

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.0.1 GitLab CE/EE (affected versions not specified)
Description A security issue in GitLab allowed attackers to achieve Denial of Service attacks through memory exhaustion. This was possible by uploading malicious artifacts.
Recommendations For versions prior to 13.0.1, update to version 13.0.1 or later to resolve the issue. As a temporary workaround, consider restricting the upload of artifacts to minimize the risk of exploitation.

Fix

Related Identifiers

BIT-GITLAB-2020-13274
CVE-2020-13274

Affected Products

Gitlab