HIGH
CVE-2020-13293
CVSS
7.1
Description
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
Summary dbcve.org
In GitLab versions prior to 13.0.12, 13.1.6, and 13.2.3, branch names containing hexadecimal characters could be mishandled due to confusion between branch references and commit SHA hashes (which are also hexadecimal). This allowed an attacker to create or manipulate a branch with a hexadecimal name to override or shadow an existing hash reference, potentially leading to reference confusion or redirect attacks.
Mitigation
Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3, or later. Additionally, review existing branches with hexadecimal names for potential abuse and implement branch naming policies to prevent future issues.
EPSS Score
1.04%
Probability of exploitation in next 30 days
62.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.