PT-2020-13434 · Gitlab · Gitlab

Retroplasma

·

Published

2020-08-10

·

Updated

2024-03-06

·

CVE-2020-13293

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.0.12 GitLab versions prior to 13.1.6 GitLab versions prior to 13.2.3
Description The issue allows an override of an existing hash when using a branch with a hexadecimal name in GitLab.
Recommendations For versions prior to 13.0.12, update to version 13.0.12 or later. For versions prior to 13.1.6, update to version 13.1.6 or later. For versions prior to 13.2.3, update to version 13.2.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-GITLAB-2020-13293
CVE-2020-13293

Affected Products

Gitlab