VulnerabilityModified
CVE-2020-13346
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
MEDIUM 6.5EPSS 1.33%
Does this matter?
Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.
Description
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.33% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-459
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13346.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/219496Broken Link
- https://hackerone.com/reports/880863Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13346.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/219496Broken Link
- https://hackerone.com/reports/880863Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.