CVE-2020-11067: Deserialization of Untrusted Data
(updated )
It has been discovered that backend user settings (in $BE_USER->uc
) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability.
References
Detect and mitigate CVE-2020-11067 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →