#VU49351 Input validation error in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2020-26414
Published: January 8, 2021
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in regex when processing package names during package uploads. A remote user can pass specially crafted input to the application and perform a regular expression denial of service (DoS) attack.