CVE-2020-13346

MEDIUM

GitLab <13.2.10-13.4.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/880863

Scores

CVSS v3 6.5
EPSS 0.0132
EPSS Percentile 67.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-459
Status published
Products (1)
gitlab/gitlab 11.2.0 - 13.2.10 (2 CPE variants)
Published Oct 07, 2020
Tracked Since Feb 18, 2026