HIGH

CVE-2020-13293

Gitlab GitLab 2020-08-10 CVSS v3.1
CVSS
7.1

Description

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

Summary dbcve.org

In GitLab versions prior to 13.0.12, 13.1.6, and 13.2.3, branch names containing hexadecimal characters could be mishandled due to confusion between branch references and commit SHA hashes (which are also hexadecimal). This allowed an attacker to create or manipulate a branch with a hexadecimal name to override or shadow an existing hash reference, potentially leading to reference confusion or redirect attacks.

Mitigation

Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3, or later. Additionally, review existing branches with hexadecimal names for potential abuse and implement branch naming policies to prevent future issues.

EPSS Score

1.04%
Probability of exploitation in next 30 days
62.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE