MEDIUM
CVE-2020-13348
CVSS
5.7
Description
An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
Summary dbcve.org
GitLab EE had a CODEOWNERS approval bypass vulnerability where required approvals could be circumvented by targeting a merge request to a branch that lacks a CODEOWNERS file, allowing unauthorized code changes to be merged without proper review.
Mitigation
Upgrade GitLab EE to versions 13.3.9, 13.4.5, 13.5.2 or later. Ensure CODEOWNERS files exist on all protected branches where approval requirements are enforced.
EPSS Score
0.8%
Probability of exploitation in next 30 days
55th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.