PT-2020-13438 · Gitlab · Gitlab

Published

2020-09-14

·

Updated

2024-03-06

·

CVE-2020-13297

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.1.10 GitLab versions prior to 13.2.8 GitLab versions prior to 13.3.4
Description A security issue was found that allows a malicious user to bypass 2-factor authentication restrictions for groups. This can be achieved by sending a specific query to an API endpoint.
Recommendations For versions prior to 13.1.10, update to version 13.1.10 or later. For versions prior to 13.2.8, update to version 13.2.8 or later. For versions prior to 13.3.4, update to version 13.3.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-GITLAB-2020-13297
CVE-2020-13297

Affected Products

Gitlab