CVE-2020-10089: High severity gitlab vulnerability
Published Mar 13, 2020
·Updated
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
Affected Software
2 affected components
GitLab GitLab>=8.11.0<=12.8.1
GitLab GitLab>=8.11.0<=12.8.1
Event History
Mar 13, 2020
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10089?
CVE-2020-10089 is classified as a Denial of Service vulnerability in GitLab.
2
How do I fix CVE-2020-10089?
To fix CVE-2020-10089, upgrade GitLab to version 12.8.2 or later.
3
Which versions are affected by CVE-2020-10089?
CVE-2020-10089 affects GitLab versions from 8.11.0 up to and including 12.8.1.
4
What features are involved in CVE-2020-10089?
CVE-2020-10089 involves several features in GitLab that can recursively request each other, leading to a denial of service.
5
Is CVE-2020-10089 related to any specific GitLab edition?
CVE-2020-10089 affects both the GitLab Community Edition and Enterprise Edition.