CRITICAL
CVE-2020-8113
CVSS
9.8
Description
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
Summary dbcve.org
GitLab versions 10.7 through 12.7.2 contains an incorrect access control vulnerability that allows unauthorized users to potentially bypass authentication or escalate privileges to access resources or functionality they should not have permission to access.
Mitigation
Upgrade GitLab to version 12.7.3 or later to remediate this access control vulnerability.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
1.38%
Probability of exploitation in next 30 days
70.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.