CVE Vulnerabilities

CVE-2020-12275

Published: Apr 29, 2020 | Modified: Jul 21, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.6.0 (including) 12.7.8 (excluding)
Gitlab Gitlab 12.8.0 (including) 12.8.8 (excluding)
Gitlab Gitlab 12.9.0 (including) 12.9.1 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References