MEDIUM

CVE-2020-13346

Gitlab GitLab 2020-10-07 CVSS v3.1
CVSS
6.5

Description

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

Summary dbcve.org

In GitLab versions prior to 13.2.10, 13.3.7, and 13.4.2, the ToDo subscription system does not properly synchronize with membership changes. When a user's project access is revoked or downgraded (e.g., from Developer to Guest), existing ToDo entries remain accessible via the API, allowing the now-revoked user to continue receiving notifications and accessing confidential issues they should no longer see.

Mitigation

Upgrade GitLab to version 13.2.10, 13.3.7, or 13.4.2 or later. Additionally, audit existing ToDo entries to ensure stale subscriptions for removed or downgraded users are revoked.

Weakness (CWE)

CWE-459

EPSS Score

1.34%
Probability of exploitation in next 30 days
69.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE