A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/340076 | broken link |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39893.json | vendor advisory |