HIGH

CVE-2020-13263

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
8.8

Description

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

Summary dbcve.org

GitLab EE versions 9.5 through 13.0.1 contain an authorization flaw that allows unauthorized users to impersonate project maintainers, potentially performing limited actions they should not have access to.

Mitigation

Upgrade GitLab EE to version 13.0.2 or later to resolve the authorization bypass that enables maintainer impersonation.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

1.02%
Probability of exploitation in next 30 days
61.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE