HIGH
CVE-2020-10088
CVSS
8.1
Description
GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.
Summary dbcve.org
This is an authorization flaw in GitLab's group permission system where invited groups could be granted incorrect (elevated) permission levels depending on specific group configuration settings. The vulnerability allows group invites to receive higher access rights than intended by the group administrators.
Mitigation
Upgrade GitLab to version 12.8.2 or later. After upgrading, audit group membership and permission settings for all invited groups to ensure they have the intended access levels.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
0.81%
Probability of exploitation in next 30 days
55.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.