MEDIUM
CVE-2020-10081
CVSS
6.5
Description
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
Summary dbcve.org
GitLab versions before 12.8.2 contain an incorrect access control vulnerability in the LFS (Large File Storage) import functionality. The LFS import process did not properly validate object ownership, potentially allowing authenticated users to access LFS objects that they do not own or have permissions for.
Mitigation
Upgrade GitLab to version 12.8.2 or later to remediate this access control vulnerability in the LFS import process.
EPSS Score
0.95%
Probability of exploitation in next 30 days
59.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.