CVE-2020-13353: Low severity gitlab vulnerability
Published Nov 17, 2020
·Updated
When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
Affected Software
3 affected components
GitLab Gitaly>=1.79.0<13.3.9
GitLab Gitaly>=13.4.0<13.4.5
GitLab Gitaly>=13.5.0<13.5.2
Event History
Nov 17, 2020
CVE Published
via MITRE·12:26 AM
Data Sourced
via MITRE·12:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13353?
CVE-2020-13353 is considered a medium severity vulnerability due to its potential exposure of sensitive git credentials.
2
How do I fix CVE-2020-13353?
To fix CVE-2020-13353, users should update Gitaly to a version above 13.5.2, 13.4.5, or 13.3.9.
3
What versions are affected by CVE-2020-13353?
CVE-2020-13353 affects Gitaly versions from 1.79.0 to 13.5.2, including 13.4.0 to 13.4.5, and 13.3.9.
4
What type of credentials does CVE-2020-13353 impact?
CVE-2020-13353 impacts one-time use git credentials that are incorrectly persisted beyond their intended lifecycle.
5
Who is affected by CVE-2020-13353?
Anyone using Gitaly versions within the specified ranges is at risk of having their git credentials inappropriately retained.