CVE-2020-13357: Medium severity gitlab vulnerability
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13357?
CVE-2020-13357 has a medium severity level due to unauthorized access vulnerabilities.
How do I fix CVE-2020-13357?
To fix CVE-2020-13357, you should upgrade GitLab to version 13.4.7 or later, 13.5.5 or later, or 13.6.2 or later.
What versions are affected by CVE-2020-13357?
CVE-2020-13357 affects GitLab CE/EE versions from 13.1 to below 13.4.7, from 13.5 to below 13.5.5, and from 13.6 to below 13.6.2.
What type of vulnerability is CVE-2020-13357?
CVE-2020-13357 is a vulnerability that allows unauthorized users to access a user list associated with a feature flag in a project.
Who is affected by CVE-2020-13357?
Organizations using vulnerable versions of GitLab CE or EE that have enabled certain feature flags may be affected by CVE-2020-13357.