HIGH
CVE-2020-8795
CVSS
7.5
Description
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
Summary dbcve.org
In GitLab Enterprise Edition versions 12.5.0 through 12.7.5, a flaw in the group sharing mechanism allowed users to gain unauthorized access to projects. When sharing a group with another group, the access control logic failed to properly enforce permission boundaries, potentially exposing sensitive project data to users who should not have access.
Mitigation
Upgrade GitLab EE to version 12.7.6 or later to patch the authorization bypass. Review audit logs to check for any unauthorized access that may have occurred while the vulnerable version was in use.
EPSS Score
1.16%
Probability of exploitation in next 30 days
65.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.