
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability identified as CVE-2020-13270 was discovered in GitLab CE/EE versions 11.3 through 13.0.1. The vulnerability stems from a missing permission check on fork relation creation functionality, which was disclosed and patched in May 2020 (GitLab Release, CVE Mitre).
The vulnerability allows guest users to create a fork relation on restricted public projects through the API endpoint, bypassing intended access controls. This security flaw exists in the project forking functionality, specifically affecting the API endpoint for creating fork relations between existing projects (GitLab Release).
The vulnerability could lead to unauthorized access to restricted project content and create inconsistencies across GitLab instances. When exploited, it could reveal information about the number of forks and default branch information that should not be visible under restricted settings (GitLab Issue).
The vulnerability could be exploited by making a POST request to the API endpoint '/projects/:id/fork/:forked_from_id' with valid authentication credentials, even with only guest-level access. This allowed bypassing the intended UI restrictions that prevented forking of restricted public projects (GitLab Issue).
The vulnerability was patched in GitLab versions 13.0.1, 12.10.7, and 12.9.8. GitLab strongly recommended that all installations running affected versions be upgraded to one of these patched versions immediately (GitLab Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."