HIGH

CVE-2020-13275

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
8.1

Description

A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

Summary dbcve.org

In GitLab EE 12.2 through 13.0.1, users with unverified email addresses could bypass domain restriction controls on groups by requesting access to those groups. Domain-restricted groups are intended to limit membership to users with email addresses from specific domains, but the access request flow did not properly validate email verification status before processing requests.

Mitigation

Upgrade to GitLab 13.0.2 or later. As a workaround, administrators should review pending access requests from unverified email users and consider disabling member invitation requests to domain-restricted groups until patched.

EPSS Score

1.04%
Probability of exploitation in next 30 days
62.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE