HIGH
CVE-2020-13334
CVSS
7.5
Description
In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query
Summary dbcve.org
Improper authorization checks in GitLab versions prior to 13.2.10, 13.3.7, and 13.4.2 allow non-members of a project or group to modify the confidentiality attribute of issues through a GraphQL mutation query, potentially exposing sensitive information.
Mitigation
Upgrade GitLab to version 13.2.10, 13.3.7, 13.4.2 or later to implement proper authorization validation on the issue confidentiality GraphQL mutation.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
1.53%
Probability of exploitation in next 30 days
73.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.