Resource exhaustion in Gitlab Community Edition - CVE-2019-10640
Published: May 15, 2019 / Updated: July 17, 2020
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.