MEDIUM
CVE-2020-12275
CVSS
5.3
Description
GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.
Summary dbcve.org
GitLab versions 12.6 through 12.9 contain an improper authorization vulnerability where external/unauthenticated users can create personal snippets via the API, allowing privilege escalation beyond their intended access level.
Mitigation
Upgrade GitLab to version 12.9.2 or later (12.10+) to remediate this vulnerability. Alternatively, restrict external API access if upgrading is not immediately feasible.
EPSS Score
1.02%
Probability of exploitation in next 30 days
62th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.