MEDIUM

CVE-2020-13348

Gitlab GitLab 2020-11-17 CVSS v3.1
CVSS
5.7

Description

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Summary dbcve.org

GitLab EE had a CODEOWNERS approval bypass vulnerability where required approvals could be circumvented by targeting a merge request to a branch that lacks a CODEOWNERS file, allowing unauthorized code changes to be merged without proper review.

Mitigation

Upgrade GitLab EE to versions 13.3.9, 13.4.5, 13.5.2 or later. Ensure CODEOWNERS files exist on all protected branches where approval requirements are enforced.

EPSS Score

0.8%
Probability of exploitation in next 30 days
55th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE