
Cloud Vulnerability DB
A community-led vulnerabilities database
A potential Denial of Service (DoS) vulnerability was discovered in GitLab versions starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). The vulnerability, identified as CVE-2020-26411, was discovered internally by the GitLab team and disclosed on December 7, 2020 (GitLab Release).
The vulnerability occurs when using a specific query name for a project search on the explore page, which can cause statement timeouts. The issue has been assigned a CVSS v3.1 Base Score of 4.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L (NVD).
If exploited, this vulnerability could lead to a potential Denial of Service condition through statement timeouts when specific search queries are executed (GitLab Release).
The vulnerability requires low attack complexity and low privileges to exploit. The attack vector is network-accessible, requiring no user interaction to execute (NVD).
GitLab strongly recommends that all installations running affected versions be upgraded to the latest version immediately. The vulnerability has been fixed in versions 13.6.2, 13.5.5, and 13.4.7 (GitLab Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."