Medium severity6.5NVD Advisory· Published Sep 30, 2020· Updated Jun 17, 2026
CVE-2020-13296
CVE-2020-13296
Description
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens
Affected products
4>=10.7 <13.0.14+ 2 more
- (no CPE)range: >=10.7 <13.0.14
- (no CPE)range: >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: <=10.7
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13296.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/235996nvdBroken Link
- hackerone.com/reports/957459nvdPermissions Required
News mentions
0No linked articles in our index yet.