First published: Wed Aug 12 2020(Updated: )
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.2.0<13.2.3 | |
GitLab | >=13.2.0<13.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13291 is considered a medium severity vulnerability due to its potential to grant excessive access to projects.
To address CVE-2020-13291, upgrade GitLab to version 13.2.3 or later.
CVE-2020-13291 affects project sharing permissions, allowing overly permissive access temporarily.
CVE-2020-13291 affects GitLab versions 13.2.0 to 13.2.2.
CVE-2020-13291 affects both GitLab Community and GitLab Enterprise editions.