CVE-2020-13348

5 documents5 sources
Severity
5.7MEDIUM
EPSS
0.1%
top 78.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateMay 24

Description

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, =13.4, =13.5, <13.5.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages2 packages

NVDgitlab/gitlab10.2.013.3.9+2
CVEListV5gitlab/gitlab_ee>=10.2, <13.3.9, >=13.4, <13.4.5, >=13.5, <13.5.2+2

🔴Vulnerability Details

2
GHSA
GHSA-vqfr-3pj8-54gm: An issue has been discovered in GitLab EE affecting all versions starting from 102022-05-24
CVEList
CVE-2020-13348: An issue has been discovered in GitLab EE affecting all versions starting from 102020-11-17

📋Vendor Advisories

2
GitLab
CVE-2020-13348: An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a bra2020-11-17
Debian
CVE-2020-13348: gitlab - An issue has been discovered in GitLab EE affecting all versions starting from 1...2020