PT-2020-13474 · Gitlab · Gitlab

Published

2020-10-06

·

Updated

2024-03-06

·

CVE-2020-13333

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GitLab versions 13.1 through 13.3
Description A potential DOS issue was discovered. The API to update an asset as a link from a release had a regex check which caused an exponential number of backtracks for certain user-supplied values, resulting in high CPU usage.
Recommendations For versions 13.1 through 13.3, update to a version that includes a fix for this issue to prevent high CPU usage due to the regex check in the API endpoint.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13333
CVE-2020-13333

Affected Products

Gitlab