HIGH

CVE-2020-13355

Gitlab GitLab 2020-11-19 CVSS v3.1
CVSS
8.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Summary dbcve.org

A path traversal vulnerability exists in GitLab's LFS (Large File Storage) upload functionality across multiple versions from 8.14 onward. The flaw allows authenticated attackers to traverse directories and overwrite specific files on the server through specially crafted LFS upload requests.

Mitigation

Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later. If immediate patching is not feasible, restrict LFS upload permissions and monitor for unauthorized file modifications.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

1.68%
Probability of exploitation in next 30 days
75.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE