First published: Fri Jun 19 2020(Updated: )
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <12.9.8 | |
GitLab | <12.9.8 | |
GitLab | >=12.10.0<12.10.7 | |
GitLab | >=12.10.0<12.10.7 | |
GitLab | =13.0.0 | |
GitLab | =13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13276 is classified as a high severity vulnerability due to the potential for unauthorized email notifications.
To mitigate CVE-2020-13276, upgrade to GitLab version 12.10.8 or later, or 13.0.1 or later.
CVE-2020-13276 affects GitLab versions prior to 12.10.8 and 13.0.1.
CVE-2020-13276 exploits the ability for users to set notification emails without email verification.
There is no official workaround for CVE-2020-13276; upgrading to a secure version is the recommended action.