CVE-2020-26412: Medium severity gitlab vulnerability
Published Dec 11, 2020
·Updated
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.
Affected Software
1 affected component
GitLab GitLab>=13.2.0<13.6.2
Event History
Dec 11, 2020
CVE Published
via MITRE·03:51 AM
Data Sourced
via MITRE·03:51 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-26412.
2
What is the severity level of CVE-2020-26412?
CVE-2020-26412 has a severity level of medium.
3
What software versions are affected by CVE-2020-26412?
Versions of GitLab EE from 13.2 to 13.6.2 are affected by CVE-2020-26412.
4
What was the impact of CVE-2020-26412?
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics.
5
How can I fix CVE-2020-26412?
To fix CVE-2020-26412, you should update GitLab EE to version 13.6.2 or higher.