ZeroHour

CVE-2020-13346

CVSS 3.1
6.5 medium
EPSS
1%p69
Published
()
Modified
Description

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

Vendors
gitlab
Products
gitlab
Weakness
CWE-459
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.