PT-2020-13492 · Gitlab · Gitlab Ce/Ee+1

Published

2020-11-17

·

Updated

2024-03-06

·

CVE-2020-13351

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.0 through 13.3.9 GitLab CE/EE versions 13.4.0 through 13.4.5 GitLab CE/EE versions 13.5.0 through 13.5.2
Description Insufficient permission checks in the scheduled pipeline API allow an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker.
Recommendations For versions 13.0 through 13.3.9, update to version 13.3.9 or later to resolve the issue. For versions 13.4.0 through 13.4.5, update to version 13.4.5 or later to resolve the issue. For versions 13.5.0 through 13.5.2, update to version 13.5.2 or later to resolve the issue.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13351
CVE-2020-13351

Affected Products

Gitlab
Gitlab Ce/Ee