#VU30134 Improper Authorization in Gitlab Authentication - CVE-2020-2228
Published: July 16, 2020
Gitlab Authentication
Jenkins
Description
The vulnerability allows a remote attacker to bypass authorization process.
The vulnerability exists due to the affected plugin does not differentiate between user names and hierarchical group names when performing authorization. A remote attacker with permissions to create groups in GitLab can gain the privileges granted to another user or group.