Resource exhaustion in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2020-26409
Published: December 10, 2020 / Updated: December 14, 2020
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when performing fields validation. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gitlab Community Edition
How to mitigate CVE-2020-26409
Gitlab Community Edition - addressed in versions 13.4.7, 13.5.5, 13.6.2