CVE-2020-13353

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*

History

13 May 2022, 14:15

Type Values Removed Values Added
Summary When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above. Affected versions are: >=1.79.0, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2. When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

Information

Published : 2020-11-17 01:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-13353

Mitre link : CVE-2020-13353

CVE.ORG link : CVE-2020-13353


JSON object : View

Products Affected

gitlab

  • gitaly
CWE
CWE-613

Insufficient Session Expiration