CVE-2020-10081 — Incorrect Authorization in Gitlab
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 77.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateMay 24
Description
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2020-10081: GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly a↗2020-03-13
Debian▶
CVE-2020-10081: gitlab - GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered ...↗2020