We found results for “”
CVE-2020-13290
Date: August 12, 2020
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Authentication Issues
CWE-287Insufficient Information
NVD-CWE-noinfoCVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | HIGH |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | LOW |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | SINGLE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |