Lucene search

K
osvGoogleOSV:CVE-2020-26414
HistoryJan 15, 2021 - 4:15 p.m.

CVE-2020-26414

2021-01-1516:15:12
Google
osv.dev
1

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

34.8%

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CPENameOperatorVersion
gitlabeq13.7.0-ee
gitlabeq13.7.1-ee

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

34.8%