Description
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- gitlab / GitLab CE/EE>=13.0 – >=13.0
- gitlab / GitLab CE/EE<13.3.9 – <13.3.9
- gitlab / GitLab CE/EE>=13.4.0 – >=13.4.0
- gitlab / GitLab CE/EE<13.4.5 – <13.4.5
- gitlab / GitLab CE/EE>=13.5.0 – >=13.5.0
- gitlab / GitLab CE/EE<13.5.2 – <13.5.2