CVE-2020-26412 - log back

CVE-2020-26412 edited at 11 Dec 2020 13:51:02
References
https://about.gitlab.com/releases/2020/12/07/security-release-gitlab-13-6-2-released/#former-group-members-able-to-view-updates-to-confidential-epics
+ https://gitlab.com/gitlab-org/gitlab/-/issues/228670
CVE-2020-26412 edited at 11 Dec 2020 13:35:39
Description
- Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2.
+ Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.
CVE-2020-26412 created at 11 Dec 2020 13:35:23
Severity
+ Low
Remote
+ Remote
Type
+ Information disclosure
Description
+ Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2.
References
+ https://about.gitlab.com/releases/2020/12/07/security-release-gitlab-13-6-2-released/#former-group-members-able-to-view-updates-to-confidential-epics
Notes