Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/55302 | broken link |
https://hackerone.com/reports/702796 | permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13264.json | vendor advisory |