HIGH

CVE-2020-13302

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
7.2

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

Summary dbcve.org

GitLab failed to properly revoke user sessions under certain conditions, allowing a malicious actor to gain unauthorized access to a user account using an old password. This is a session management and authentication bypass vulnerability where session state was not correctly invalidated upon password changes.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, or 13.3.4 or later to ensure proper session revocation upon password changes.

Weakness (CWE)

CWE-613

EPSS Score

1.13%
Probability of exploitation in next 30 days
65th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE