CVE-2020-13341

MEDIUM

GitLab <13.2.10-13.4.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions.

References (3)

Core 3
Core References
Broken Link, Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab/-/issues/239348
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/960244

Scores

CVSS v3 4.9
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-843
Status published
Products (1)
gitlab/gitlab 13.1.0 - 13.2.10 (2 CPE variants)
Published Oct 12, 2020
Tracked Since Feb 18, 2026