MEDIUM
CVE-2020-12277
CVSS
5.3
Description
GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.
Summary dbcve.org
Broken access control in GitLab versions 10.8-12.9 allows authenticated users to enable repository mirroring even when the feature has been disabled by administrators. This bypasses intended access controls configured at the instance or project level.
Mitigation
Upgrade GitLab to version 12.9.1 or later to receive the security patch. After upgrading, verify that repository mirroring controls function as expected per administrative settings.
Weakness (CWE)
CWE-276
Incorrect Default Permissions
EPSS Score
0.77%
Probability of exploitation in next 30 days
54.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.