MEDIUM

CVE-2020-10535

Gitlab GitLab 2020-03-12 CVSS v3.1
CVSS
5.3

Description

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

Summary dbcve.org

GitLab versions 12.8.x before 12.8.6 contain an authentication bypass vulnerability where email domain restrictions can be circumvented during a two-day grace period for unconfirmed email addresses when user sign-up is enabled. An attacker could register with a restricted domain email and bypass domain whitelist/blacklist controls within this window.

Mitigation

Upgrade to GitLab 12.8.6 or later. If immediate upgrade is not possible, consider disabling sign-ups or implementing additional monitoring for suspicious registration patterns during the grace period.

EPSS Score

1.02%
Probability of exploitation in next 30 days
61.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE