CVE Vulnerabilities

CVE-2020-13346

Incomplete Cleanup

Published: Oct 07, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab11.2.0 (including)13.2.10 (excluding)
GitlabGitlab13.3.0 (including)13.3.7 (excluding)
GitlabGitlab13.4.0 (including)13.4.2 (excluding)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntuxenial*

Potential Mitigations

References