PT-2020-13417 · Gitlab · Gitlab Ce/Ee+1

Published

2020-06-19

·

Updated

2024-03-06

·

CVE-2020-13276

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 13.0.1
Description The issue allows a user to set an email as a notification email without verifying the new email.
Recommendations For versions prior to 13.0.1, update to version 13.0.1 or later to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13276
CVE-2020-13276

Affected Products

Gitlab
Gitlab Ce/Ee