CRITICAL

CVE-2020-10083

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
9.1

Description

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

Summary dbcve.org

GitLab versions 12.7 through 12.8.1 contain an insecure permissions vulnerability where project authorization changes involving groups were not being properly applied. This authorization bypass could allow users to retain access to projects they should no longer have permission to view or modify.

Mitigation

Upgrade GitLab to version 12.8.2 or later to remediate the authorization bypass. After upgrading, audit existing group-project membership to ensure permissions are correctly enforced.

Weakness (CWE)

CWE-281

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE