CVE-2020-13325: Input Validation
Published Sep 29, 2020
·Updated
A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.
Affected Software
3 affected components
GitLab GitLab>=12.9.0<12.10.13
GitLab GitLab>=13.0.0<13.0.8
GitLab GitLab>=13.1.0<13.1.2
Event History
Sep 29, 2020
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13325?
CVE-2020-13325 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2020-13325?
To fix CVE-2020-13325, you should upgrade GitLab to version 13.1.3 or later.
3
What versions of GitLab are affected by CVE-2020-13325?
CVE-2020-13325 affects GitLab versions prior to 13.1, specifically versions between 12.9.0 and 12.10.13 and 13.0.0 to 13.0.8, and 13.1.0 to 13.1.2.
4
What are the potential consequences of CVE-2020-13325?
CVE-2020-13325 can lead to a denial of service due to improper character restriction in the comment section.
5
Can CVE-2020-13325 be exploited remotely?
Yes, CVE-2020-13325 can be exploited remotely since it affects the comment section on the issue page of GitLab.