MEDIUM

CVE-2020-13265

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
5.3

Description

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

Summary dbcve.org

This vulnerability allows users to bypass email verification in GitLab CE/EE versions 12.5 through 13.0.1. An attacker could potentially create accounts or gain unauthorized access without completing the required email verification process.

Mitigation

Upgrade GitLab to version 13.0.2 or later per the official GitLab security advisory. Review user accounts created during the affected timeframe for unverified or suspicious activity.

Weakness (CWE)

CWE-345

EPSS Score

0.73%
Probability of exploitation in next 30 days
52.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE