MEDIUM
CVE-2020-11649
CVSS
6.5
Description
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
Summary dbcve.org
A broken access control vulnerability in GitLab CE and EE versions 8.15 through 12.9.2 allows group members to retain access to resources after their parent group is deleted. The group deletion process fails to properly revoke member permissions, leaving stale authorizations in place.
Mitigation
Upgrade GitLab to version 12.9.3 or later, and conduct an access review to identify and manually revoke any lingering member permissions from deleted groups.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
0.81%
Probability of exploitation in next 30 days
55.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.