MEDIUM

CVE-2020-10952

Gitlab GitLab 2020-03-27 CVSS v3.1
CVSS
6.5

Description

GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

Summary dbcve.org

GitLab EE/CE versions 8.11 through 12.9.1 contains an authorization bypass where users who have been blocked in GitLab can still authenticate to the integrated Docker Registry and pull/push container images. The block status is not properly enforced on Docker registry operations.

Mitigation

Upgrade GitLab to version 12.9.2 or later where this vulnerability is patched. Alternatively, if immediate upgrade is not feasible, consider restricting or disabling the Docker registry temporarily until the upgrade can be performed.

EPSS Score

0.75%
Probability of exploitation in next 30 days
53.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE