CVE-2020-13276
19.06.2020, 22:15
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 𝑥 < 12.9.8 |
gitlab | gitlab | 𝑥 < 12.9.8 |
gitlab | gitlab | 12.10.0 ≤ 𝑥 < 12.10.7 |
gitlab | gitlab | 12.10.0 ≤ 𝑥 < 12.10.7 |
gitlab | gitlab | 13.0.0 |
gitlab | gitlab | 13.0.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References