VYPR
Unrated severityNVD Advisory· Published Apr 8, 2020· Updated Aug 4, 2024

CVE-2020-10981

CVE-2020-10981

Description

GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In GitLab 9.0 to 12.9, a project maintainer can modify another maintainer's pipeline trigger description, bypassing intended permissions.

Vulnerability

In GitLab EE/CE versions 9.0 through 12.9, a project maintainer can modify the pipeline trigger description of another maintainer within the same project. This vulnerability allows a user with the Maintainer role to alter pipeline trigger descriptions that were created by other Maintainers, which should normally require the original author's privileges or additional permissions. The issue affects all instances running the affected versions.

Exploitation

To exploit this vulnerability, an attacker must have the Maintainer role in a GitLab project that uses pipeline triggers. The attacker can navigate to the pipeline triggers settings and modify the description of another maintainer's trigger. The user interaction required is limited to accessing the project settings and performing the modification; no special timing or race conditions are involved. The attacker does not need to know the trigger token or have access to the trigger itself beyond the project settings.

Impact

Successful exploitation allows the attacker to change the description of another maintainer's pipeline trigger. This can lead to confusion or misdirection regarding the purpose of the trigger, potentially enabling social engineering or subtle manipulation of CI/CD processes. It does not directly allow code execution or data exfiltration, but it violates the principle of least privilege and could be used to obscure malicious changes to pipeline configurations.

Mitigation

GitLab addressed this vulnerability in version 12.9.1, released on March 26, 2020 [2]. Users running GitLab 9.0 through 12.9 should upgrade to 12.9.1 or later to apply the fix. No workarounds are documented, and as of the publication date, this CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.