PT-2020-13495 · Gitlab · Gitlab Ce/Ee+1

Published

2020-11-17

·

Updated

2024-03-06

·

CVE-2020-13354

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 12.6 through 13.3.8
Description A potential DOS issue was discovered in GitLab CE/EE. The container registry name check could cause an exponential number of backtracks for certain user-supplied values, resulting in high CPU usage.
Recommendations For versions 12.6 through 13.3.8, update to version 13.3.9 or later to resolve the issue. As a temporary workaround, consider restricting user input for the container registry name check to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13354
CVE-2020-13354

Affected Products

Gitlab
Gitlab Ce/Ee