CVE-2020-13356
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de 8.8.9. Una petición especialmente diseñada podría omitir una protección Multipart y leer archivos en determinadas rutas específicas en el servidor. Las versiones afectadas son: versiones posteriores a 8.8.9 incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 incluyéndola, versiones anteriores a 13.5.2
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-21 CVE Reserved
- 2020-11-18 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/230878 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13356.json | 2020-12-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 8.8.9 < 13.3.9 Search vendor "Gitlab" for product "Gitlab" and version " >= 8.8.9 < 13.3.9" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 8.8.9 < 13.3.9 Search vendor "Gitlab" for product "Gitlab" and version " >= 8.8.9 < 13.3.9" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 13.4.0 < 13.4.5 Search vendor "Gitlab" for product "Gitlab" and version " >= 13.4.0 < 13.4.5" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 13.4.0 < 13.4.5 Search vendor "Gitlab" for product "Gitlab" and version " >= 13.4.0 < 13.4.5" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 13.5.0 < 13.5.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 13.5.0 < 13.5.2" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 13.5.0 < 13.5.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 13.5.0 < 13.5.2" | enterprise |
Affected
|