PT-2020-13448 · Gitlab · Gitlab

Published

2020-09-15

·

Updated

2024-03-06

·

CVE-2020-13307

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.1.10 GitLab versions prior to 13.2.8 GitLab versions prior to 13.3.4
Description A security issue was found in GitLab where it failed to revoke current user sessions when two-factor authentication was activated, allowing a malicious user to maintain access.
Recommendations For versions prior to 13.1.10, update to version 13.1.10 or later. For versions prior to 13.2.8, update to version 13.2.8 or later. For versions prior to 13.3.4, update to version 13.3.4 or later.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13307
CVE-2020-13307

Affected Products

Gitlab