CVE-2020-10088: GitLab

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

Affected products

  • GitLab GitLab: from 12.5.0, up to and including 12.8.1

Published 2020-03-13. Last modified 2026-06-17.