Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-5606 | Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-04T12:18:17.541Z
Reserved: 2020-05-21T00:00:00.000Z
Link: CVE-2020-13346
No data.
Status : Modified
Published: 2020-10-07T14:15:11.747
Modified: 2024-11-21T05:01:05.080
Link: CVE-2020-13346
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD