CVE-2020-13353 describes a vulnerability in GitLab's Gitaly component (versions 1.79.0 and above) where one-time Git credentials, used during repository imports via URL, were improperly persisted beyond their intended lifespan. This is a low-severity vulnerability with a CVSS score of 3.2, requiring high privileges and local access to exploit, potentially leading to limited confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.79.0, < 13.3.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:* | ||
>= 13.4.0, < 13.4.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:* | ||
>= 13.5.0, < 13.5.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.