CVE-2020-13299 PUBLISHED

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

EPSS 0.19% · 40.3th percentile

Risk Scores

EPSS Score
0.19%
40.3th percentile

Affected Products

VendorProductVersions
Bitnamigitlab13.3.0, 13.3.0, 1.0.0
Bitnamigitlab13.2.0, 13.3.0, 1.0.0

Timeline

References

Open in Interactive Console →