HIGH
CVE-2020-13356
CVSS
8.2
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
Summary dbcve.org
A path traversal vulnerability in GitLab CE/EE allows authenticated users to bypass Multipart protection and read files from specific paths on the server via specially crafted requests. This file read issue affects versions 8.8.9 through 13.5.1.
Mitigation
Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later. If immediate patching is not possible, restrict file system access and review authentication controls for GitLab instances.
EPSS Score
1.79%
Probability of exploitation in next 30 days
77.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.