A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/220019 | broken link |
https://hackerone.com/reports/869875 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13354.json | vendor advisory |