HIGH

CVE-2020-13334

Gitlab GitLab 2020-10-07 CVSS v3.1
CVSS
7.5

Description

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query

Summary dbcve.org

Improper authorization checks in GitLab versions prior to 13.2.10, 13.3.7, and 13.4.2 allow non-members of a project or group to modify the confidentiality attribute of issues through a GraphQL mutation query, potentially exposing sensitive information.

Mitigation

Upgrade GitLab to version 13.2.10, 13.3.7, 13.4.2 or later to implement proper authorization validation on the issue confidentiality GraphQL mutation.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

1.53%
Probability of exploitation in next 30 days
73.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE