GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-13T16:54:45
Updated: 2024-08-04T10:50:57.889Z
Reserved: 2020-03-04T00:00:00
Link: CVE-2020-10081
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-13T17:15:11.940
Modified: 2024-11-21T04:54:46.180
Link: CVE-2020-10081
Redhat
No data.