CVE-2020-10535: GitLab
Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
Affected products
- GitLab GitLab: from 12.8.0, before 12.8.6 (fixed in 12.8.6)
Published 2020-03-12. Last modified 2026-06-17.