CVE-2020-13353

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.5 LOW
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
GitLabCNA
2.5 LOW
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
gitlabgitaly
1.79.0 ≤
𝑥
< 13.3.9
gitlabgitaly
13.4.0 ≤
𝑥
< 13.4.5
gitlabgitaly
13.5.0 ≤
𝑥
< 13.5.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gitaly
sid
16.8.2+ds3-2
fixed
trixie
16.8.2+ds3-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gitaly
groovy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne