Impact
GitLab allows an authenticated user to trigger a denial of service by exploiting missing limits on object allocation, causing background job processing to fail. The flaw is a classic example of CWE‑770, where uncontrolled resource consumption can degrade or halt system functionality.
Affected Systems
The vulnerability affects all GitLab Community and Enterprise editions from version 12.8 through the released patch versions 19.1.7, 19.2.5, and 19.3.1. Any installation using a GitLab version earlier than these PPG releases is susceptible.
Risk and Exploitability
With a CVSS score of 6.5, the security impact is moderate and the attack requires authenticated access. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, implying a lower public exploitation likelihood. Nonetheless, an attacker who can authenticate could intentionally overload the system’s background job queue, leading to service disruption.
OpenCVE Enrichment