CRITICAL

CVE-2020-10074

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
9.8

Description

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

Summary dbcve.org

GitLab versions 10.1 through 12.8.1 contain an incorrect access control vulnerability where expired authentication links (likely password reset or email verification tokens) remain valid beyond their expiration, allowing attackers to hijack accounts by reusing stale links.

Mitigation

Upgrade GitLab to version 12.8.2 or later to remediate the access control flaw. Review and rotate any potentially compromised account credentials as a precautionary measure.

EPSS Score

1.28%
Probability of exploitation in next 30 days
68.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE