MEDIUM
CVE-2020-10079
CVSS
5.3
Description
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.
Summary dbcve.org
GitLab versions 7.10 through 12.8.1 contained an incorrect access control vulnerability where two-factor authentication was not being enforced for users under certain conditions where it should have been required, allowing potentially unauthorized access.
Mitigation
Upgrade to GitLab 12.8.2 or later (or a currently supported version), and verify that 2FA policies are properly configured and enforced across the instance.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
0.86%
Probability of exploitation in next 30 days
56.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.