GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due to missing object count limits.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 6
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
12.8.0
|
19.1.7
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
12.8.0
|
19.1.7
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
19.2.0
|
19.2.5
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
19.2.0
|
19.2.5
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:community:*:*:*
|
— | — |
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*
|
— | — |