CVE-2020-13298
Last modified
CVE-2020-13298 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | < 13.1.10 |
| Gitlab | Gitlab | >= 13.2.0, < 13.2.8 |
| Gitlab | Gitlab | >= 13.3.0, < 13.3.4 |
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13298.jsonThird Party Advisory
- https://hackerone.com/reports/923027Permissions Required
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13298.jsonThird Party Advisory
- https://hackerone.com/reports/923027Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-13298?
How severe is CVE-2020-13298?
How do I fix CVE-2020-13298?
Are you affected by CVE-2020-13298?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
