First published: Fri Mar 13 2020(Updated: )
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=7.10.0<=12.8.1 | |
GitLab | >=7.10.0<=12.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10079 has been classified as a high-severity vulnerability due to incorrect access control in GitLab.
To fix CVE-2020-10079, you should upgrade your GitLab instance to version 12.8.2 or later where the issue has been addressed.
CVE-2020-10079 affects GitLab versions from 7.10 through 12.8.1.
CVE-2020-10079 is an access control vulnerability that impacts user authentication.
The potential impact of CVE-2020-10079 includes unauthorized access for users who should be required to enable two-factor authentication.