MEDIUM

CVE-2020-13298

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
5.8

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.

Summary dbcve.org

GitLab's Conan package manager integration contains a parameter validation flaw in the package upload functionality. By supplying specially crafted parameters during Conan package upload, an attacker could access files outside the intended package scope, resulting in limited file disclosure.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later. If upgrading is not immediately possible, restrict Conan package upload functionality to trusted users only.

EPSS Score

1.24%
Probability of exploitation in next 30 days
67.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE