CVE-2020-35236: Amazee Lagoon

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.

Affected products

  • Amazee Lagoon: before 1.12.3 (fixed in 1.12.3)

Published 2020-12-14. Last modified 2026-06-17.