Critical severity9.8NVD Advisory· Published Mar 13, 2020· Updated Jun 17, 2026
CVE-2020-10074
CVE-2020-10074
Description
GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=10.1.0,<=12.8.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=10.1.0,<=12.8.1
- (no CPE)range: 10.1 - 12.8.1
- GitLab/GitLabdescription
Patches
Vulnerability mechanics
References
2- about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/nvdRelease NotesVendor Advisory
- about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.