PT-2020-12191 · Gitlab · Gitlab

Published

2020-03-12

·

Updated

2024-03-06

·

CVE-2020-10535

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 12.8.x through 12.8.5
Description The issue allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address when sign-up is enabled.
Recommendations For GitLab versions 12.8.x through 12.8.5, update to version 12.8.6 or later to resolve the issue.

Fix

Related Identifiers

BIT-GITLAB-2020-10535
CVE-2020-10535

Affected Products

Gitlab