MEDIUM

CVE-2020-10081

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
6.5

Description

GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

Summary dbcve.org

GitLab versions before 12.8.2 contain an incorrect access control vulnerability in the LFS (Large File Storage) import functionality. The LFS import process did not properly validate object ownership, potentially allowing authenticated users to access LFS objects that they do not own or have permissions for.

Mitigation

Upgrade GitLab to version 12.8.2 or later to remediate this access control vulnerability in the LFS import process.

EPSS Score

0.95%
Probability of exploitation in next 30 days
59.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE