CVE Vulnerabilities

CVE-2020-13307

Insufficient Session Expiration

Published: Sep 15, 2020 | Modified: Sep 18, 2020
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 13.1.0 (including) 13.1.10 (excluding)
Gitlab Gitlab 13.2.0 (including) 13.2.8 (excluding)
Gitlab Gitlab 13.3.0 (including) 13.3.4 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *
Gitlab Ubuntu xenial *

Potential Mitigations

References