First published: Wed Apr 08 2020(Updated: )
GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=9.0.0<=12.9 | |
GitLab | >=9.0.0<=12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10981 has a medium severity rating due to the potential for privilege escalation within GitLab projects.
To fix CVE-2020-10981, upgrade GitLab to version 12.9.1 or later.
Users of GitLab EE/CE versions 9.0 to 12.9 are affected by CVE-2020-10981.
CVE-2020-10981 is a privilege escalation vulnerability in GitLab allowing maintainers to modify pipeline trigger descriptions.
CVE-2020-10981 can be exploited locally by maintainers within the same GitLab project.