PT-2020-9365 · Gitlab · Gitlab Ce/Ee+1
Ashish_R_Padelkar
·
Published
2020-03-10
·
Updated
2020-08-24
·
CVE-2019-13011
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GitLab Enterprise Edition versions 8.11.0 through 12.0.2
Description:
An issue was discovered that allows a user with access to a project, but not its repository, to create a list of merge requests template names using brute-force. The issue has excessive algorithmic complexity.
Recommendations:
For GitLab Enterprise Edition versions 8.11.0 through 12.0.2, consider restricting access to merge requests template names to prevent brute-force attacks until a fix is available.
As a temporary workaround, consider implementing rate limiting on API endpoints related to merge requests to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee