CVE-2020-10079 (NVD)

2020-03-13

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

Products Gitlab
Type Missing Authentication for Critical Function (CWE-306)
First patch - None (likely due to unavailable code)
Links https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/
https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html