PT-2020-13453 · Gitlab · Gitlab

Published

2020-09-14

·

Updated

2024-03-06

·

CVE-2020-13312

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.1.10 GitLab versions prior to 13.2.8 GitLab versions prior to 13.3.4
Description A vulnerability was discovered that allows brute-force attacks through a specific parameter in the GitLab OAuth endpoint.
Recommendations For versions prior to 13.1.10, update to version 13.1.10 or later. For versions prior to 13.2.8, update to version 13.2.8 or later. For versions prior to 13.3.4, update to version 13.3.4 or later.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13312
CVE-2020-13312

Affected Products

Gitlab