CVE Vulnerabilities

CVE-2020-13324

Published: Sep 30, 2020 | Modified: Oct 08, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 9.4.0 (including) 12.10.13 (excluding)
Gitlab Gitlab 13.0.0 (including) 13.0.8 (excluding)
Gitlab Gitlab 13.1.0 (including) 13.1.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References