Gitlab · Gitlab · CVE-2020-13302
**Name of the Vulnerable Software and Affected Versions**
GitLab versions prior to 13.1.10
GitLab versions prior to 13.2.8
GitLab versions prior to 13.3.4
**Description**
A vulnerability was discovered that allows a malicious user to access a user account with an old password under certain conditions, due to GitLab not properly revoking user sessions.
**Recommendations**
For versions prior to 13.1.10, update to version 13.1.10 or later.
For versions prior to 13.2.8, update to version 13.2.8 or later.
For versions prior to 13.3.4, update to version 13.3.4 or later.