#VU28324 Permissions, Privileges, and Access Controls in GitLab Enterprise Edition
Published: May 28, 2020
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the way application deletes mirror projects. A remote attacker can impersonate owners of deleted projects.
Please note that the edit project API endpoint has been restricted and only admin users have the ability to set the mirror_user_id