CVE-2020-13313
4.3
MEDIUM
CVSS 3.1
EPSS 0.15%
Description
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.
How to fix CVE-2020-13313
To remediate CVE-2020-13313, upgrade the affected package to a fixed version below.
- Bitnami/gitlab—upgrade to 13.1.10 or later
Is CVE-2020-13313 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.0.0, < 13.1.10, >= 13.2.0, < 13.2.8, >= 13.3.0, < 13.3.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |