PT-2020-13423 · Gitlab · Gitlab

Kryword

·

Published

2020-08-13

·

Updated

2024-03-06

·

CVE-2020-13282

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.0.12 GitLab versions prior to 13.1.6 GitLab versions prior to 13.2.3
Description The issue arises after a group transfer occurs, where members from a parent group retain their access level on the subgroup, resulting in improper access.
Recommendations For versions prior to 13.0.12, update to version 13.0.12 or later. For versions prior to 13.1.6, update to version 13.1.6 or later. For versions prior to 13.2.3, update to version 13.2.3 or later.

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13282
CVE-2020-13282

Affected Products

Gitlab