CVE-2020-13298: High severity gitlab vulnerability
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13298?
CVE-2020-13298 is identified as a medium severity vulnerability that can lead to limited file disclosure.
How do I fix CVE-2020-13298?
To mitigate CVE-2020-13298, upgrade your GitLab installation to versions 13.1.10, 13.2.8, or 13.3.4 or later.
What specific GitLab versions are affected by CVE-2020-13298?
CVE-2020-13298 affects GitLab versions prior to 13.1.10, between 13.2.0 and 13.2.8, and between 13.3.0 and 13.3.4.
What type of vulnerability is CVE-2020-13298?
CVE-2020-13298 is a parameter validation vulnerability within the Conan package upload functionality.
Who should be concerned about CVE-2020-13298?
Organizations using affected versions of GitLab should be concerned about CVE-2020-13298 due to the potential risk of limited files disclosure.