PT-2020-13464 · Gitlab · Gitlab

Gitlab Team

·

Published

2020-09-29

·

Updated

2024-03-06

·

CVE-2020-13323

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.1
Description A vulnerability was discovered that allows private merge requests to be read via Todos under certain conditions.
Recommendations For versions prior to 13.1, update to version 13.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-GITLAB-2020-13323
CVE-2020-13323

Affected Products

Gitlab