First published: Fri Jun 19 2020(Updated: )
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.2.0<12.9.8 | |
GitLab | >=12.2.0<12.9.8 | |
GitLab | >=12.10.0<12.10.7 | |
GitLab | >=12.10.0<12.10.7 | |
GitLab | =13.0.0 | |
GitLab | =13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13275 has a severity rating of Medium, indicating a moderate level of risk.
To mitigate CVE-2020-13275, users should upgrade to GitLab version 12.9.9 or later for 12.x or 13.0.1 or later for 13.x.
CVE-2020-13275 allows a user with an unverified email address to request access to domain-restricted groups.
CVE-2020-13275 affects GitLab versions from 12.2.0 through 13.0.0 but is addressed in later versions.
No specific workaround is provided for CVE-2020-13275, so upgrading is the recommended action.