| Severity | 
						
							
						 | 
					
					
						| Remote | 
						
							
						 | 
					
					
						| Type | 
						
							
								
									| - | 
									Unknown | 
								 
								
									| + | 
									Access restriction bypass | 
								 
							 
						 | 
					
					
						| Description | 
						
							
								
									| + | 
									An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects. The issue is fixed in GitLab versions 13.10.1, 13.9.5 and 13.8.7. | 
								 
							 
						 | 
					
					
						| References | 
						
							
								
									| + | 
									https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/#incident-metric-images-can-be-deleted-by-any-user | 
								 
								
									| + | 
									https://gitlab.com/gitlab-org/gitlab/-/issues/323452 | 
								 
								
									| + | 
									https://hackerone.com/reports/1107281 | 
								 
							 
						 | 
					
					
						| Notes | 
						
							
						 |