Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-08-04T15:56:04.357Z

Reserved: 2020-10-01T00:00:00

Link: CVE-2020-26412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-11T04:15:11.487

Modified: 2024-11-21T05:19:53.133

Link: CVE-2020-26412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.