CVE-2020-13346

MEDIUM

GitLab <13.2.10-13.4.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-459
Status published
Products (1)
gitlab/gitlab 11.2.0 - 13.2.10 (2 CPE variants)
Published Oct 07, 2020
Tracked Since Feb 18, 2026