Vulnerabilities > CVE-2020-13334 - Incorrect Authorization vulnerability in Gitlab

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
gitlab
CWE-863

Summary

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query

Vulnerable Configurations

Part Description Count
Application
Gitlab
1437

Common Weakness Enumeration (CWE)