HIGH

CVE-2020-13304

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
7.2

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.

Summary dbcve.org

GitLab before versions 13.1.10, 13.2.8, and 13.3.4 had a flaw in its 2FA implementation where the same authentication secret code was being generated. This predictability allowed attackers to potentially bypass 2FA and maintain unauthorized access to accounts under certain conditions.

Mitigation

Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later to receive the fix for the predictable 2FA secret generation vulnerability.

Weakness (CWE)

CWE-330

EPSS Score

1.62%
Probability of exploitation in next 30 days
75th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE