CVE-2020-10079Missing Authentication for Critical Function in Gitlab

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 84.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateMay 24

Description

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

debiandebian/gitlab< gitlab 12.6.8-3 (sid)
NVDgitlab/gitlab7.10.012.8.1
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-3jmg-94rq-h4hm: GitLab 72022-05-24
OSV
CVE-2020-10079: GitLab 72020-03-13

📋Vendor Advisories

2
GitLab
CVE-2020-10079: GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authen2020-03-13
Debian
CVE-2020-10079: gitlab - GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain condition...2020