CVE-2020-13352 The advisory has been revoked - it doesn't affect any version of package gitlab  (opens in a new tab)


Threat Intelligence

EPSS
0.13% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1604-GITLAB-1035834
  • published4 Nov 2020
  • disclosed17 Nov 2020

Introduced: 4 Nov 2020

CVE-2020-13352  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:16.04.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gitlab package and not the gitlab package as distributed by Ubuntu.

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.