CVE-2020-13275 HIGH

CVE-2020-13275

Vendor Gitlab
Product GitLab
Published June 19, 2020
Last update August 4, 2024

CVSS base score

8.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

Key dates

02Disclosure timeline

June 19, 2020 CVE published
August 4, 2024 Record updated