First published: Tue Nov 26 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.0.0<=12.4.0 | |
GitLab | >=11.0.0<=12.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18455 has a severity rating of high due to the potential for large or infinite loop scenarios.
To fix CVE-2019-18455, upgrade your GitLab instance to version 12.4.1 or later.
CVE-2019-18455 affects GitLab Community and Enterprise Editions from version 11.0.0 up to 12.4.0.
The potential impacts of CVE-2019-18455 include performance degradation and service outages caused by infinite loops in Nested GraphQL queries.
As of my knowledge cutoff, there have been no widespread reports of active exploitation of CVE-2019-18455.