HIGH
CVE-2020-13302
CVSS
7.2
Description
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.
Summary dbcve.org
GitLab failed to properly revoke user sessions under certain conditions, allowing a malicious actor to gain unauthorized access to a user account using an old password. This is a session management and authentication bypass vulnerability where session state was not correctly invalidated upon password changes.
Mitigation
Upgrade GitLab to version 13.1.10, 13.2.8, or 13.3.4 or later to ensure proper session revocation upon password changes.
Weakness (CWE)
CWE-613
EPSS Score
1.13%
Probability of exploitation in next 30 days
65th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.