CVE-2020-13263: GitLab
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
Affected products
- GitLab GitLab: from 9.5.0, before 12.9.8 (fixed in 12.9.8); from 12.10.0, before 12.10.7 (fixed in 12.10.7); version 13.0.0 only
Published 2020-06-19. Last modified 2026-06-17.