MEDIUM

CVE-2020-13277

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
6.5

Description

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

Summary dbcve.org

An authorization flaw in GitLab's repository mirroring feature allowed authenticated users to read contents of private repositories they should not have access to, by exploiting the mirroring logic to bypass access controls.

Mitigation

Upgrade GitLab to version 13.0.6 or later to patch the authorization bypass in the mirroring logic.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

1.85%
Probability of exploitation in next 30 days
78.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE