CVE-2020-8595: Improper Authentication
(updated )
The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ?
or #
character to a URI that would otherwise satisfy an exact-path match.
References
Detect and mitigate CVE-2020-8595 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →