PT-2020-13496 · Gitlab · Gitlab Ce/Ee+1

Published

2020-11-18

·

Updated

2024-03-06

·

CVE-2020-13355

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.14 through 13.3.8 GitLab CE/EE versions 13.4 through 13.4.4 GitLab CE/EE versions 13.5 through 13.5.1
Description An issue has been discovered in GitLab CE/EE that affects all versions starting from 8.14. A path traversal is found in LFS Upload that allows an attacker to overwrite certain specific paths on the server.
Recommendations For versions 8.14 through 13.3.8, update to version 13.3.9 or later. For versions 13.4 through 13.4.4, update to version 13.4.5 or later. For versions 13.5 through 13.5.1, update to version 13.5.2 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-13355
CVE-2020-13355

Affected Products

Gitlab
Gitlab Ce/Ee