CVE-2020-13291Gitlab vulnerability

4 documents4 sources
Severity
8.1HIGHNVD
EPSS
0.1%
top 73.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateMay 24

Description

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages4 packages

NVDgitlab/gitlab13.2.013.2.3
CVEListV5gitlab/gitlab>=13.2, <13.2.3
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-q49w-v89m-366g: In GitLab before 132022-05-24

📋Vendor Advisories

2
GitLab
CVE-2020-13291: In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.2020-08-12
Debian
CVE-2020-13291: gitlab - In GitLab before 13.2.3, project sharing could temporarily allow too permissive ...2020