CVE-2020-11649 (NVD)

2020-04-22

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

Products Gitlab
Type Missing Authentication for Critical Function (CWE-306)
First patch - None (likely due to unavailable code)
Links https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/
https://about.gitlab.com/blog/categories/releases/