CVE-2020-11649
Description
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
GitLab CE/EE 8.15 through 12.9.2 allowed deleted group members to retain access, fixed in 12.9.3.
Vulnerability
In GitLab Community Edition (CE) and Enterprise Edition (EE) versions 8.15 through 12.9.2, when a group is deleted, the group's members were not properly removed from associated projects and resources. This allowed former group members to retain access to group-owned projects and other resources even after the group was deleted. The issue affects all versions in the range 8.15 to 12.9.2 inclusive.
Exploitation
An attacker who was a member of a group could continue to access group resources after the group was deleted. No additional authentication or privileges are required beyond being a member of the group before deletion. The exploitation occurs when a group is deleted but the member's access rights are not revoked, allowing continued access to projects, issues, merge requests, and other resources that were previously shared with the group.
Impact
Successful exploitation results in unauthorized access to group-owned resources, including potential information disclosure of sensitive project data, source code, and other confidential information. The attacker retains the same level of access they had as a group member, which could include read, write, or admin privileges depending on their role within the group. This violates the expected security boundary that deleting a group should remove all associated access.
Mitigation
The issue is fixed in GitLab version 12.9.3, released on April 14, 2020 [1]. Users should upgrade to 12.9.3 or later. No workaround is available for versions prior to the fix. Users on older versions should upgrade as soon as possible.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- GitLab/GitLab CE and EEdescription
- Range: 8.15 through 12.9.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- about.gitlab.com/blog/categories/releases/mitrex_refsource_MISC
- about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.