CVE-2020-26412 log

Source
Severity Low
Remote Yes
Type Information disclosure
Description
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.
Group Package Affected Fixed Severity Status Ticket
AVG-1347 gitlab 13.6.1-1 13.6.2-1 Medium Not affected
References
https://about.gitlab.com/releases/2020/12/07/security-release-gitlab-13-6-2-released/#former-group-members-able-to-view-updates-to-confidential-epics
https://gitlab.com/gitlab-org/gitlab/-/issues/228670