MEDIUM

CVE-2020-13352

Gitlab GitLab 2020-11-17 CVSS v3.1
CVSS
5.3

Description

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Summary dbcve.org

In GitLab CE/EE versions 10.2 through 13.5.2, private group information is inadvertently leaked when a project is moved from a private group to a public group, exposing sensitive group metadata that should remain confidential.

Mitigation

Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later to patch the vulnerability, and audit group/project visibility settings for potential exposure.

EPSS Score

1.22%
Probability of exploitation in next 30 days
67.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE