A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "13.1.10"
},
{
"introduced": "13.2.0"
},
{
"fixed": "13.2.8"
},
{
"introduced": "13.3.0"
},
{
"fixed": "13.3.4"
}
],
"cpe": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE"
}