MEDIUM

CVE-2020-11649

Gitlab GitLab 2020-04-22 CVSS v3.1
CVSS
6.5

Description

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

Summary dbcve.org

A broken access control vulnerability in GitLab CE and EE versions 8.15 through 12.9.2 allows group members to retain access to resources after their parent group is deleted. The group deletion process fails to properly revoke member permissions, leaving stale authorizations in place.

Mitigation

Upgrade GitLab to version 12.9.3 or later, and conduct an access review to identify and manually revoke any lingering member permissions from deleted groups.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

0.81%
Probability of exploitation in next 30 days
55.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE