CRITICAL
CVE-2020-10083
CVSS
9.1
Description
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
Summary dbcve.org
GitLab versions 12.7 through 12.8.1 contain an insecure permissions vulnerability where project authorization changes involving groups were not being properly applied. This authorization bypass could allow users to retain access to projects they should no longer have permission to view or modify.
Mitigation
Upgrade GitLab to version 12.8.2 or later to remediate the authorization bypass. After upgrading, audit existing group-project membership to ensure permissions are correctly enforced.
Weakness (CWE)
CWE-281
EPSS Score
1.08%
Probability of exploitation in next 30 days
63.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.