Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/208449 | broken link |
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13266.json | third party advisory |