Impact
GitLab contains a logic flaw that allows an authenticated user to trigger an unbounded loop in the SCIM provisioning handler. The loop occurs when the user supplies specially crafted input, leading the application to consume resources indefinitely. This results in a denial of service, preventing the system from processing further requests and potentially causing service interruption for all users.
Affected Systems
All GitLab Enterprise Edition instances from version 11.10 up to, but excluding, 19.1.7, 19.2 versions before 19.2.5, and 19.3 versions before 19.3.1 are vulnerable. This includes every release in that range, regardless of the installation method or environment.
Risk and Exploitability
The risk is moderate: the CVSS score of 6.5 reflects an authentication requirement and a denial of service impact. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, indicating limited evidence of exploitation. An attacker must be authenticated and craft specific input to the SCIM endpoint; therefore, the attack vector is likely an internal or compromised account. Mitigation requires applying the vendor‑issued patch, after which the risk is eliminated.
OpenCVE Enrichment