CVE-2020-13307 PUBLISHED

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.

EPSS 0.17% · 38.2th percentile

Risk Scores

EPSS Score
0.17%
38.2th percentile

Affected Products

VendorProductVersions
Bitnamigitlab13.3.0, 13.3.0, 1.0.0
Bitnamigitlab13.2.0, 13.3.0, 1.0.0

Timeline

References

Open in Interactive Console →