Input validation error in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2020-26414
Published: January 8, 2021
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in regex when processing package names during package uploads. A remote user can pass specially crafted input to the application and perform a regular expression denial of service (DoS) attack.
Affected software
Gitlab Community Edition
Arch Linux
How to mitigate CVE-2020-26414
Gitlab Community Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2