HIGH

CVE-2020-26405

Gitlab GitLab 2020-11-17 CVSS v3.1
CVSS
7.1

Description

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Summary dbcve.org

A path traversal vulnerability in GitLab CE/EE's package upload functionality (starting version 12.8) allows authenticated attackers to save packages in arbitrary filesystem locations by manipulating file paths during upload. This could lead to arbitrary file write on the server.

Mitigation

Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later. If immediate patching is not possible, restrict package upload permissions and monitor for suspicious upload patterns.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

1.45%
Probability of exploitation in next 30 days
72.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE