A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/118536 | broken link |
https://hackerone.com/reports/751264 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13313.json | vendor advisory |