PT-2020-13440 · Gitlab · Gitlab

Published

2020-09-14

·

Updated

2024-03-06

·

CVE-2020-13299

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.1.10 GitLab versions prior to 13.2.8 GitLab versions prior to 13.3.4
Description A vulnerability was discovered where the revocation feature was not revoking all session tokens, allowing them to be re-used to obtain a valid session.
Recommendations For versions prior to 13.1.10, update to version 13.1.10 or later. For versions prior to 13.2.8, update to version 13.2.8 or later. For versions prior to 13.3.4, update to version 13.3.4 or later.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13299
CVE-2020-13299

Affected Products

Gitlab