MEDIUM

CVE-2020-13284

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
6.5

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

Summary dbcve.org

GitLab versions before 13.1.10, 13.2.8, and 13.3.4 contain a vulnerability where CI job tokens used for API authorization are not properly invalidated after they become outdated, allowing potentially unauthorized API access using stale tokens.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. Alternatively, review and rotate any CI job tokens that may have been exposed or used prior to patching.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

1.1%
Probability of exploitation in next 30 days
64.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE