PT-2020-13445 · Gitlab · Gitlab

Published

2020-09-14

·

Updated

2024-03-06

·

CVE-2020-13304

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.1.10 GitLab versions prior to 13.2.8 GitLab versions prior to 13.3.4
Description A vulnerability was discovered where the same 2-factor Authentication secret code was generated, allowing an attacker to maintain access under certain conditions.
Recommendations For versions prior to 13.1.10, update to version 13.1.10 or later. For versions prior to 13.2.8, update to version 13.2.8 or later. For versions prior to 13.3.4, update to version 13.3.4 or later.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13304
CVE-2020-13304

Affected Products

Gitlab