First published: Tue Sep 29 2020(Updated: )
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <=10.7 | |
GitLab | >=13.0.0<13.0.14 | |
GitLab | >=13.1.0<13.1.8 | |
GitLab | >=13.2.0<13.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13296 has a CVSS score that indicates moderate severity due to improper access control for deploy tokens.
To fix CVE-2020-13296, upgrade GitLab to version 13.0.14 or later, or to 13.1.8 or later, or to 13.2.6 or later.
CVE-2020-13296 affects GitLab versions greater than or equal to 10.7 but less than 13.0.14, and specific ranges in 13.1.x and 13.2.x.
CVE-2020-13296 is classified as an improper access control vulnerability, specifically related to deploy tokens in GitLab.
There have been no reports indicating active exploitation of CVE-2020-13296 in the wild.