Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2020-10952
Published:
Mar 27, 2020
| Modified:
Jul 21, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2020-10952
CWE
https://cwe.mitre.org/data/definitions/.html
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
Affected Software
Name
Vendor
Start Version
End Version
Gitlab
Gitlab
8.11.0 (including)
12.9.1 (including)
References
https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/
https://about.gitlab.com/releases/categories/releases/
Aqua Container Security