VulnerabilityModified
CVE-2020-10081
GitLab before 12.8.2 has Incorrect Access Control.
MEDIUM 6.5EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@mitre.org
References
- https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/Release Notes, Vendor Advisory
- https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.htmlRelease Notes, Vendor Advisory
- https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/Release Notes, Vendor Advisory
- https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.