CVE-2020-13334
07.10.2020, 14:15
In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL queryEnginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 8.6.0 ≤ 𝑥 < 13.2.10 |
gitlab | gitlab | 8.6.0 ≤ 𝑥 < 13.2.10 |
gitlab | gitlab | 13.3.0 ≤ 𝑥 < 13.3.7 |
gitlab | gitlab | 13.3.0 ≤ 𝑥 < 13.3.7 |
gitlab | gitlab | 13.4.0 ≤ 𝑥 < 13.4.2 |
gitlab | gitlab | 13.4.0 ≤ 𝑥 < 13.4.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References