GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-2546 | GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:50:57.889Z
Reserved: 2020-03-04T00:00:00
Link: CVE-2020-10081
No data.
Status : Modified
Published: 2020-03-13T17:15:11.940
Modified: 2024-11-21T04:54:46.180
Link: CVE-2020-10081
No data.
OpenCVE Enrichment
No data.
EUVD