CVE-2020-26409: Input Validation
Published Dec 11, 2020
·Updated
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
Affected Software
6 affected components
GitLab GitLab>=10.3.0<13.4.7
GitLab GitLab>=10.3.0<13.4.7
GitLab GitLab>=13.5.0<13.5.5
GitLab GitLab>=13.5.0<13.5.5
GitLab GitLab>=13.6.0<13.6.2
GitLab GitLab>=13.6.0<13.6.2
Event History
Dec 11, 2020
CVE Published
via MITRE·01:17 AM
Data Sourced
via MITRE·01:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26409?
CVE-2020-26409 is classified as a denial-of-service (DoS) vulnerability.
2
Which versions of GitLab are affected by CVE-2020-26409?
CVE-2020-26409 affects GitLab CE/EE versions from 10.3 to 13.4.7, 13.5 to 13.5.5, and 13.6 to 13.6.2.
3
How do I fix CVE-2020-26409?
To address CVE-2020-26409, upgrade your GitLab instance to the latest version beyond 13.4.7, 13.5.5, or 13.6.2.
4
What type of attack is possible due to CVE-2020-26409?
CVE-2020-26409 allows attackers to trigger uncontrolled resource consumption through input validation bypass in markdown fields.
5
How can I verify if I am impacted by CVE-2020-26409?
You can verify your GitLab version against the affected versions listed under CVE-2020-26409.