CVE-2020-13298Improper Input Validation in Gitlab

Severity
5.8MEDIUMNVD
EPSS
0.3%
top 44.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14
Latest updateMay 24

Description

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDgitlab/gitlab13.2.013.2.8+2
debiandebian/gitlab< gitlab 13.2.8-1 (sid)
CVEListV5gitlab/gitlab>=13.1, <13.1.10, >=13.2, <13.2.8, >=13.3, <13.3.4+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-6x4g-3g6f-c363: A vulnerability was discovered in GitLab versions before 132022-05-24
OSV
CVE-2020-13298: A vulnerability was discovered in GitLab versions before 132020-09-14

📋Vendor Advisories

2
GitLab
CVE-2020-13298: A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating th2020-09-14
Debian
CVE-2020-13298: gitlab - A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13....2020