PT-2020-13475 · Gitlab · Gitlab

Published

2020-10-07

·

Updated

2024-03-06

·

CVE-2020-13334

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.2.10 GitLab versions prior to 13.3.7 GitLab versions prior to 13.4.2
Description The issue is related to improper authorization checks in GitLab, allowing a non-member of a project or group to modify the confidentiality attribute of an issue. This can be achieved via a mutation GraphQL query.
Recommendations For versions prior to 13.2.10, update to version 13.2.10 or later. For versions prior to 13.3.7, update to version 13.3.7 or later. For versions prior to 13.4.2, update to version 13.4.2 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13334
CVE-2020-13334

Affected Products

Gitlab