CVE-2020-13352 is a medium-severity information leakage vulnerability affecting GitLab CE/EE versions 10.2 and above. Specifically, it impacts versions 10.2 to 13.3.8, 13.4 to 13.4.4, and 13.5 to 13.5.1. This flaw allows private group information to be exposed if a project is moved from a private to a public group. The vulnerability has a CVSS score of 5.3, indicating a medium severity. It is easily exploitable over the network with low attack complexity and no user interaction required, leading to a potential loss of confidentiality (C:L). There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. While there is limited community discussion and media coverage, the vulnerability is not listed on the CISA KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.2.0, < 13.3.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 10.2.0, < 13.3.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 13.4.0, < 13.4.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 13.4.0, < 13.4.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 13.5.0, < 13.5.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.