CVE-2020-7978 is a Denial of Service vulnerability affecting GitLab Enterprise Edition versions 12.6 through 12.7.2. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, leading to a complete denial of service without requiring user interaction or privileges. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Despite limited community discussion, it has received some media coverage, primarily from GitLab's security release announcements.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.6.0, < 12.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 12.7.0, <= 12.7.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.