VulnerabilityModified
CVE-2020-13319
Missing permission check for adding time spent on an issue.
MEDIUM 4.3EPSS 0.78%
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13319.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/201806Exploit, Vendor Advisory
- https://hackerone.com/reports/755188Permissions Required
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13319.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/201806Exploit, Vendor Advisory
- https://hackerone.com/reports/755188Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.