CVE-2020-10804: SQL Injection
(updated )
An SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php
and libraries/classes/UserPassword.php
). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).
References
Detect and mitigate CVE-2020-10804 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →