First published: Fri Jun 19 2020(Updated: )
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=10.6.0<=13.0.5 | |
GitLab | >=10.6.0<=13.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13277 is rated as a medium severity vulnerability due to its potential unauthorized access to private repositories.
To fix CVE-2020-13277, upgrade GitLab to version 13.0.6 or later.
CVE-2020-13277 affects GitLab CE/EE versions from 10.6.0 up to and including 13.0.5.
CVE-2020-13277 is categorized as an authorization issue affecting the mirroring logic in GitLab.
CVE-2020-13277 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.