MEDIUM
CVE-2020-10535
CVSS
5.3
Description
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
Summary dbcve.org
GitLab versions 12.8.x before 12.8.6 contain an authentication bypass vulnerability where email domain restrictions can be circumvented during a two-day grace period for unconfirmed email addresses when user sign-up is enabled. An attacker could register with a restricted domain email and bypass domain whitelist/blacklist controls within this window.
Mitigation
Upgrade to GitLab 12.8.6 or later. If immediate upgrade is not possible, consider disabling sign-ups or implementing additional monitoring for suspicious registration patterns during the grace period.
EPSS Score
1.02%
Probability of exploitation in next 30 days
61.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.