MEDIUM

CVE-2020-10079

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
5.3

Description

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

Summary dbcve.org

GitLab versions 7.10 through 12.8.1 contained an incorrect access control vulnerability where two-factor authentication was not being enforced for users under certain conditions where it should have been required, allowing potentially unauthorized access.

Mitigation

Upgrade to GitLab 12.8.2 or later (or a currently supported version), and verify that 2FA policies are properly configured and enforced across the instance.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

0.86%
Probability of exploitation in next 30 days
56.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE