GitLab устранил проблему в GitLab CE/EE, затрагивающую все версии с 12.8 до 19.1.7, 19.2 до 19.2.5 и 19.3 до 19.3.1, которая при определенных условиях могла позволить аутентифицированному пользователю вызвать отказ в обслуживании, влияющий на обработку фоновых заданий, из-за отсутствия ограничений на количество объектов.
Показать оригинальное описание (EN)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due to missing object count limits.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 6
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
12.8.0
|
19.1.7
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
12.8.0
|
19.1.7
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
19.2.0
|
19.2.5
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
19.2.0
|
19.2.5
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:community:*:*:*
|
— | — |
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*
|
— | — |