HIGH
CVE-2020-13304
CVSS
7.2
Description
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.
Summary dbcve.org
GitLab before versions 13.1.10, 13.2.8, and 13.3.4 had a flaw in its 2FA implementation where the same authentication secret code was being generated. This predictability allowed attackers to potentially bypass 2FA and maintain unauthorized access to accounts under certain conditions.
Mitigation
Upgrade GitLab to version 13.1.10, 13.2.8, 13.3.4 or later to receive the fix for the predictable 2FA secret generation vulnerability.
Weakness (CWE)
CWE-330
EPSS Score
1.62%
Probability of exploitation in next 30 days
75th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.