High severity7.2NVD Advisory· Published Sep 14, 2020· Updated Jun 17, 2026
CVE-2020-13298
CVE-2020-13298
Description
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.
Affected products
4>=13.3, <13.3.4+ 2 more
- (no CPE)range: >=13.3, <13.3.4
- (no CPE)range: <13.1.10, 13.2.8, 13.3.4
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: <13.1.10
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13298.jsonnvdThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/228841nvdBroken Link
- hackerone.com/reports/923027nvdPermissions Required
News mentions
0No linked articles in our index yet.