CVE Vulnerabilities

CVE-2020-13265

Insufficient Verification of Data Authenticity

Published: Jun 19, 2020 | Modified: Jun 26, 2020
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.5.0 (including) 12.9.8 (excluding)
Gitlab Gitlab 12.10.0 (including) 12.10.7 (excluding)
Gitlab Gitlab 13.0.0 (including) 13.0.0 (including)

References