A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.
{
"cpe": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "13.4.0"
},
{
"fixed": "13.4.7"
},
{
"introduced": "13.5.0"
},
{
"fixed": "13.5.5"
},
{
"introduced": "13.6.0"
},
{
"fixed": "13.6.2"
}
],
"source": "CPE_RANGE"
}