HIGH

CVE-2020-13356

Gitlab GitLab 2020-11-19 CVSS v3.1
CVSS
8.2

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Summary dbcve.org

A path traversal vulnerability in GitLab CE/EE allows authenticated users to bypass Multipart protection and read files from specific paths on the server via specially crafted requests. This file read issue affects versions 8.8.9 through 13.5.1.

Mitigation

Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later. If immediate patching is not possible, restrict file system access and review authentication controls for GitLab instances.

EPSS Score

1.79%
Probability of exploitation in next 30 days
77.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE