HIGH
CVE-2020-13355
CVSS
8.1
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
Summary dbcve.org
A path traversal vulnerability exists in GitLab's LFS (Large File Storage) upload functionality across multiple versions from 8.14 onward. The flaw allows authenticated attackers to traverse directories and overwrite specific files on the server through specially crafted LFS upload requests.
Mitigation
Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later. If immediate patching is not feasible, restrict LFS upload permissions and monitor for unauthorized file modifications.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
1.68%
Probability of exploitation in next 30 days
75.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.