MEDIUM

CVE-2020-15525

Gitlab GitLab 2020-07-07 CVSS v3.1
CVSS
5.3

Description

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

Summary dbcve.org

GitLab EE versions 11.3 through 13.1.2 contain an incorrect access control vulnerability in the Maven package upload endpoint, potentially allowing unauthorized users to upload Maven packages to projects or repositories they shouldn't have access to.

Mitigation

Upgrade GitLab EE to version 13.1.3 or later to resolve the access control issue in the Maven package upload functionality.

EPSS Score

1.06%
Probability of exploitation in next 30 days
63th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE