CVE-2020-10073 — Missing Authorization in Gitlab
Severity
7.5HIGHNVD
EPSS
0.1%
top 71.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateMay 24
Description
GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
1📋Vendor Advisories
2GitLab▶
CVE-2020-10073: GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks↗2020-03-13
Debian▶
CVE-2020-10073: gitlab - GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally disc...↗2020