CVE-2020-11649: Medium severity gitlab vulnerability
Published Apr 22, 2020
·Updated
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
Affected Software
6 affected components
GitLab GitLab>=8.15.0<12.7.9
GitLab GitLab>=8.15.0<12.7.9
GitLab GitLab>=12.8.0<12.8.9
GitLab GitLab>=12.8.0<12.8.9
GitLab GitLab>=12.9.0<12.9.3
GitLab GitLab>=12.9.0<12.9.3
Event History
Apr 22, 2020
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11649?
CVE-2020-11649 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-11649?
To fix CVE-2020-11649, upgrade GitLab to a version higher than 12.9.3.
3
What versions of GitLab are affected by CVE-2020-11649?
CVE-2020-11649 affects GitLab CE and EE versions from 8.15 through 12.9.2.
4
What type of vulnerability is CVE-2020-11649?
CVE-2020-11649 is a security vulnerability that allows unauthorized access after group deletion.
5
Can users access GitLab after a group is deleted due to CVE-2020-11649?
Yes, users may retain access to the GitLab instance even after their group has been deleted.