HIGH

CVE-2020-8795

Gitlab GitLab 2020-02-17 CVSS v3.1
CVSS
7.5

Description

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

Summary dbcve.org

In GitLab Enterprise Edition versions 12.5.0 through 12.7.5, a flaw in the group sharing mechanism allowed users to gain unauthorized access to projects. When sharing a group with another group, the access control logic failed to properly enforce permission boundaries, potentially exposing sensitive project data to users who should not have access.

Mitigation

Upgrade GitLab EE to version 12.7.6 or later to patch the authorization bypass. Review audit logs to check for any unauthorized access that may have occurred while the vulnerable version was in use.

EPSS Score

1.16%
Probability of exploitation in next 30 days
65.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE