Improper Authentication in Gitlab Community Edition - CVE-2020-13297
Published: September 15, 2020 / Updated: September 18, 2020
Gitlab Community Edition
GitLab, Inc
Description
The vulnerability allows a remote authenticated user to read and manipulate data.
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restriction by sending a specific query to the API endpoint.