CVE-2019-10640: Command Injection
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10640?
CVE-2019-10640 is classified as having a medium severity due to its potential for uncontrolled resource consumption.
How do I fix CVE-2019-10640?
To fix CVE-2019-10640, upgrade to GitLab versions 11.7.10, 11.8.6, or 11.9.4 or later.
What systems are affected by CVE-2019-10640?
CVE-2019-10640 affects GitLab Community and Enterprise Editions prior to version 11.7.10, 11.8.x prior to 11.8.6, and 11.9.x prior to 11.9.4.
What type of vulnerability is CVE-2019-10640?
CVE-2019-10640 is a regex input validation issue that can lead to uncontrolled resource consumption.
Is CVE-2019-10640 still a risk if I've updated my GitLab?
If you've updated your GitLab instance to the recommended versions, CVE-2019-10640 should no longer pose a risk.