MEDIUM
CVE-2020-13284
CVSS
6.5
Description
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token
Summary dbcve.org
GitLab versions before 13.1.10, 13.2.8, and 13.3.4 contain a vulnerability where CI job tokens used for API authorization are not properly invalidated after they become outdated, allowing potentially unauthorized API access using stale tokens.
Mitigation
Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. Alternatively, review and rotate any CI job tokens that may have been exposed or used prior to patching.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
1.1%
Probability of exploitation in next 30 days
64.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.