RubySec

Providing security resources for the Ruby community

CVE-2021-39880 (apollo_upload_server): apollo_upload_server has Denial of Service vulnerability

ADVISORIES

GEM

apollo_upload_server

SEVERITY

CVSS v3.x: 6.5 (Medium)

PATCHED VERSIONS

  • >= 2.1.0

DESCRIPTION

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE version 11.11 and above allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

RELATED