PT-2020-13493 · Gitlab · Gitlab Ce/Ee+1

Published

2020-11-17

·

Updated

2024-03-06

·

CVE-2020-13352

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 10.2 through 13.3.8 GitLab CE/EE versions 13.4 through 13.4.4 GitLab CE/EE versions 13.5 through 13.5.1
Description Private group information is leaked in GitLab CE/EE when a project is moved from a private to a public group.
Recommendations For versions 10.2 through 13.3.8, update to version 13.3.9 or later to resolve the issue. For versions 13.4 through 13.4.4, update to version 13.4.5 or later to resolve the issue. For versions 13.5 through 13.5.1, update to version 13.5.2 or later to resolve the issue.

Fix

Related Identifiers

BIT-GITLAB-2020-13352
CVE-2020-13352

Affected Products

Gitlab
Gitlab Ce/Ee