CRITICAL
CVE-2020-10074
CVSS
9.8
Description
GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.
Summary dbcve.org
GitLab versions 10.1 through 12.8.1 contain an incorrect access control vulnerability where expired authentication links (likely password reset or email verification tokens) remain valid beyond their expiration, allowing attackers to hijack accounts by reusing stale links.
Mitigation
Upgrade GitLab to version 12.8.2 or later to remediate the access control flaw. Review and rotate any potentially compromised account credentials as a precautionary measure.
EPSS Score
1.28%
Probability of exploitation in next 30 days
68.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.