CVE-2020-10079

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
13/03/2020
Last modified:
18/03/2020

Description

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 7.10.0 (including) 12.8.1 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 7.10.0 (including) 12.8.1 (including)