Description
An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-18961 | An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string. |
References
History
No history.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-04T15:56:04.447Z
Reserved: 2020-10-01T00:00:00.000Z
Link: CVE-2020-26414
No data.
Status : Modified
Published: 2021-01-15T16:15:12.967
Modified: 2024-11-21T05:19:53.510
Link: CVE-2020-26414
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD