MEDIUM
CVE-2020-10952
CVSS
6.5
Description
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
Summary dbcve.org
GitLab EE/CE versions 8.11 through 12.9.1 contains an authorization bypass where users who have been blocked in GitLab can still authenticate to the integrated Docker Registry and pull/push container images. The block status is not properly enforced on Docker registry operations.
Mitigation
Upgrade GitLab to version 12.9.2 or later where this vulnerability is patched. Alternatively, if immediate upgrade is not feasible, consider restricting or disabling the Docker registry temporarily until the upgrade can be performed.
EPSS Score
0.75%
Probability of exploitation in next 30 days
53.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.