CVE-2020-13346
07.10.2020, 14:15
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 11.2.0 ≤ 𝑥 < 13.2.10 |
gitlab | gitlab | 11.2.0 ≤ 𝑥 < 13.2.10 |
gitlab | gitlab | 13.3.0 ≤ 𝑥 < 13.3.7 |
gitlab | gitlab | 13.3.0 ≤ 𝑥 < 13.3.7 |
gitlab | gitlab | 13.4.0 ≤ 𝑥 < 13.4.2 |
gitlab | gitlab | 13.4.0 ≤ 𝑥 < 13.4.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References