gitlab.comConfirmation
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13357.json CVE-2020-13357
MEDIUM
Record summary
CVE-2020-13357 has a selected CVSS score of 4.3 (medium).
Description
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GitLab CE/EEBrowse GitLab / GitLab CE/EE | CVE List | >= 13.1 to <13.4.7 | affected |
| >= 13.5 to <13.5.5 | affected | ||
| >= 13.6 to <13.6.2 | affected |
References
4gitlab.com
https://gitlab.com/gitlab-org/gitlab/-/issues/241132 hackerone.com
https://hackerone.com/reports/962408 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-13357