HIGH
CVE-2020-13291
CVSS
8.1
Description
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
Summary dbcve.org
In GitLab before 13.2.3, the project sharing feature contained a vulnerability where access permissions could temporarily be more permissive than intended during the sharing process, likely due to a race condition or timing issue in permission assignment.
Mitigation
Upgrade GitLab to version 13.2.3 or later to resolve the improper access control during project sharing.
EPSS Score
0.96%
Probability of exploitation in next 30 days
59.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.