Code Approval Bypass in GitLab EE
CVE-2020-13348
5.7MEDIUM
Summary
A vulnerability exists in GitLab EE that allows an attacker to bypass CODEOWNERS file approval requirements. This issue impacts all versions starting from 10.2 and affects branches that do not contain the CODEOWNERS file, ultimately enabling unauthorized access to make changes without proper approval. Users are strongly advised to upgrade to patched versions to mitigate potential risks.
Affected Version(s)
GitLab EE >=10.2, <13.3.9 < 10.2, 13.3.9
GitLab EE >=13.4, <13.4.5 < 13.4, 13.4.5
GitLab EE >=13.5, <13.5.2 < 13.5, 13.5.2
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by the GitLab team