Related Vulnerabilities: CVE-2021-22168  

A regular expression denial of service issue has been discovered in the NuGet API affecting all versions of GitLab starting from version 12.8. The issue is mitigated in GitLab version 13.7.2, 13.6.4, and 13.5.6.

Severity Medium

Remote Yes

Type Denial of service

Description

A regular expression denial of service issue has been discovered in the NuGet API affecting all versions of GitLab starting from version 12.8. The issue is mitigated in GitLab version 13.7.2, 13.6.4, and 13.5.6.

AVG-1416 gitlab 13.7.1-1 13.7.2-1 High Fixed

12 Jan 2021 ASA-202101-10 AVG-1416 gitlab High multiple issues

https://about.gitlab.com/releases/2021/01/07/security-release-gitlab-13-7-2-released/#regular-expression-denial-of-service-in-nuget-api