MEDIUM

CVE-2020-12277

Gitlab GitLab 2020-04-29 CVSS v3.1
CVSS
5.3

Description

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

Summary dbcve.org

Broken access control in GitLab versions 10.8-12.9 allows authenticated users to enable repository mirroring even when the feature has been disabled by administrators. This bypasses intended access controls configured at the instance or project level.

Mitigation

Upgrade GitLab to version 12.9.1 or later to receive the security patch. After upgrading, verify that repository mirroring controls function as expected per administrative settings.

Weakness (CWE)

CWE-276 Incorrect Default Permissions

EPSS Score

0.77%
Probability of exploitation in next 30 days
54.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE