Vulnerabilities > CVE-2020-35236 - Missing Authorization vulnerability in Amazee Lagoon

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
amazee
CWE-862

Summary

The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.

Common Weakness Enumeration (CWE)