PT-2020-9365 · Gitlab · Gitlab Ce/Ee+1

Ashish_R_Padelkar

·

Published

2020-03-10

·

Updated

2020-08-24

·

CVE-2019-13011

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab Enterprise Edition versions 8.11.0 through 12.0.2
Description: An issue was discovered that allows a user with access to a project, but not its repository, to create a list of merge requests template names using brute-force. The issue has excessive algorithmic complexity.
Recommendations: For GitLab Enterprise Edition versions 8.11.0 through 12.0.2, consider restricting access to merge requests template names to prevent brute-force attacks until a fix is available. As a temporary workaround, consider implementing rate limiting on API endpoints related to merge requests to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13011

Affected Products

Gitlab
Gitlab Ce/Ee