MEDIUM
CVE-2020-13277
CVSS
6.5
Description
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
Summary dbcve.org
An authorization flaw in GitLab's repository mirroring feature allowed authenticated users to read contents of private repositories they should not have access to, by exploiting the mirroring logic to bypass access controls.
Mitigation
Upgrade GitLab to version 13.0.6 or later to patch the authorization bypass in the mirroring logic.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
1.85%
Probability of exploitation in next 30 days
78.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.