PT-2020-13088 · Gitlab · Gitlab

Published

2020-04-29

·

Updated

2024-03-06

·

CVE-2020-12275

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 12.6 through 12.9
Description The issue allows an external user to create a personal snippet through the API, resulting in a privilege escalation.
Recommendations For GitLab versions 12.6 through 12.9, update to a version that contains a fix for this issue to prevent privilege escalation. As a temporary workaround, consider restricting access to the API endpoint that allows creating personal snippets until a patch is available.

Fix

Related Identifiers

BIT-GITLAB-2020-12275
CVE-2020-12275

Affected Products

Gitlab