PT-2020-13437 · Gitlab · Gitlab

Published

2020-09-29

·

Updated

2024-03-06

·

CVE-2020-13296

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GitLab versions 10.7 through 13.0.13 GitLab versions 13.1.0 through 13.1.7 GitLab versions 13.2.0 through 13.2.5
Description An issue has been discovered in GitLab related to Improper Access Control for Deploy Tokens.
Recommendations For GitLab versions 10.7 through 13.0.13, update to version 13.0.14 or later. For GitLab versions 13.1.0 through 13.1.7, update to version 13.1.8 or later. For GitLab versions 13.2.0 through 13.2.5, update to version 13.2.6 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13296
CVE-2020-13296

Affected Products

Gitlab