First published: Fri Mar 27 2020(Updated: )
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.11.0<=12.9.1 | |
GitLab | >=8.11.0<=12.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10952 has a medium severity rating as it allows blocked users to pull or push Docker images.
To fix CVE-2020-10952, upgrade GitLab EE/CE to version 12.9.2 or later.
CVE-2020-10952 affects GitLab EE/CE versions from 8.11.0 up to 12.9.1.
CVE-2020-10952 impacts GitLab users who have blocked accounts but may still access Docker images.
CVE-2020-10952 details a vulnerability that allows blocked users unauthorized access to push or pull Docker images on GitLab.