HIGH

CVE-2020-10088

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
8.1

Description

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

Summary dbcve.org

This is an authorization flaw in GitLab's group permission system where invited groups could be granted incorrect (elevated) permission levels depending on specific group configuration settings. The vulnerability allows group invites to receive higher access rights than intended by the group administrators.

Mitigation

Upgrade GitLab to version 12.8.2 or later. After upgrading, audit group membership and permission settings for all invited groups to ensure they have the intended access levels.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

0.81%
Probability of exploitation in next 30 days
55.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE