CVE-2020-13353

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-13353
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13353.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13353
Aliases
Published
2020-11-17T01:15:13Z
Modified
2025-04-09T05:53:06.360446Z
Severity
  • 3.2 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

References

Affected packages

Debian:13 / gitaly

Package

Name
gitaly
Purl
pkg:deb/debian/gitaly?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
13.3.9-1

Affected versions

1.*

1.58.0+dfsg-1
1.58.0+dfsg-2
1.59.3+dfsg-1
1.59.3+dfsg-2
1.65.2+dfsg-1
1.67.1+dfsg-1
1.72.1+dfsg-1
1.72.1+dfsg-2
1.78.0+dfsg-1
1.78.0+dfsg-2
1.86.0+dfsg1-1

12.*

12.9.2+dfsg-1
12.9.2+dfsg-2
12.9.3+dfsg-1
12.10.0+dfsg-1

13.*

13.0.0+dfsg-1
13.0.6+dfsg-1
13.1.0+dfsg-1
13.2.1+dfsg-1
13.2.1+dfsg-2
13.2.1+dfsg-3
13.3.0+dfsg-1
13.3.0+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / gitlab.com/gitlab-org/gitaly

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitaly
Events

Affected versions

v1.*

v1.79.0
v1.80.0
v1.81.0
v1.82.0
v1.83.0
v1.84.0
v1.85.0
v1.86.0
v1.87.0

v12.*

v12.10.0
v12.10.0-rc1
v12.8.0
v12.8.0-rc42
v12.9.0
v12.9.0-rc1
v12.9.0-rc2
v12.9.0-rc3
v12.9.0-rc4
v12.9.0-rc42
v12.9.0-rc5

v13.*

v13.0.0
v13.0.0-rc1
v13.0.0-rc2
v13.1.0
v13.1.0-rc1
v13.1.0-rc2
v13.1.0-rc3
v13.1.0-rc4
v13.2.0
v13.2.0-rc1
v13.2.0-rc2
v13.3.0
v13.3.0-rc1
v13.3.0-rc2
v13.3.0-rc3
v13.3.0-rc4
v13.3.0-rc5
v13.3.1
v13.3.2
v13.3.3
v13.3.4
v13.3.5
v13.3.6
v13.3.7
v13.3.8