CVE-2020-13266

MEDIUM

GitLab CE/EE <13.0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0006
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-862
Status published
Products (1)
gitlab/gitlab 12.8 - 13.0.1 (2 CPE variants)
Published Jun 09, 2020
Tracked Since Feb 18, 2026