CVE-2020-11649: GitLab
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
Affected products
- GitLab GitLab: from 8.15.0, before 12.7.9 (fixed in 12.7.9); from 12.8.0, before 12.8.9 (fixed in 12.8.9); from 12.9.0, before 12.9.3 (fixed in 12.9.3)
Published 2020-04-22. Last modified 2026-06-17.