PT-2020-13411 · Gitlab · Gitlab Ce/Ee+1

CVE-2020-13270

·

Published

2020-06-10

·

Updated

2024-03-06

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 11.3 through 13.0.1
Description A missing permission check on fork relation creation in GitLab CE/EE allows guest users to create a fork relation on restricted public projects via the API.
Recommendations For GitLab CE/EE versions 11.3 through 13.0.1, update to a version that includes the fix for this issue to prevent guest users from creating fork relations on restricted public projects.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13270
CVE-2020-13270

Affected Products

Gitlab
Gitlab Ce/Ee