HIGH
CVE-2020-13275
CVSS
8.1
Description
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
Summary dbcve.org
In GitLab EE 12.2 through 13.0.1, users with unverified email addresses could bypass domain restriction controls on groups by requesting access to those groups. Domain-restricted groups are intended to limit membership to users with email addresses from specific domains, but the access request flow did not properly validate email verification status before processing requests.
Mitigation
Upgrade to GitLab 13.0.2 or later. As a workaround, administrators should review pending access requests from unverified email users and consider disabling member invitation requests to domain-restricted groups until patched.
EPSS Score
1.04%
Probability of exploitation in next 30 days
62.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.