MEDIUM

CVE-2020-13289

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
5.4

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

Summary dbcve.org

GitLab versions before 13.1.10, 13.2.8, and 13.3.4 contain a validation flaw where invalid usernames could be accepted during the two-factor authentication (2FA) process, potentially allowing authentication bypass in certain scenarios.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, or 13.3.4 or later to patch the username validation vulnerability in the 2FA authentication flow.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

0.69%
Probability of exploitation in next 30 days
51.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE