« Volver al listado

CVE-2020-13353

Estado: ModificadaBaja (3.2)—

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-13353",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 2.5,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 0.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 3.2,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "vendor": "GitLab",
          "product": "Gitaly",
          "versions": [
            {
              "status": "affected",
              "version": ">=1.79.0, <13.3.9"
            },
            {
              "status": "affected",
              "version": ">=13.4, <13.4.5"
            },
            {
              "status": "affected",
              "version": ">=13.5, <13.5.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-11-17T01:15:13.310",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13353.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitaly/-/issues/2882",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13353.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitaly/-/issues/2882",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-613"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above."
    },
    {
      "lang": "es",
      "value": "Cuando se importa repositorios por medio de URL, las credenciales git de un solo uso se mantenían más allá de la ventana de tiempo esperada en Gitaly 1.79.0 o superior."
    }
  ],
  "lastModified": "2026-06-17T02:53:00.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14B63381-3635-4C77-A556-E6515829A265",
              "versionEndExcluding": "13.3.9",
              "versionStartIncluding": "1.79.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5E8AE21-2790-4A73-85FF-D85D1558007C",
              "versionEndExcluding": "13.4.5",
              "versionStartIncluding": "13.4.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8F11B88-8B47-462B-A8E4-3B706CFA8592",
              "versionEndExcluding": "13.5.2",
              "versionStartIncluding": "13.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}