CVE-2019-13011: GitLab
Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.
Affected products
- GitLab GitLab: from 8.11.0, up to and including 12.0.2
Published 2020-03-10. Last modified 2026-06-17.