CVE-2020-13297
GitLab vulnerability analysis and mitigation

Overview

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4 that allowed bypassing two-factor authentication (2FA) requirements for groups. When 2FA was enabled for groups, malicious users could circumvent this security restriction by sending specific queries to the API endpoint (GitLab Release, NVD).

Technical details

The vulnerability stemmed from improper validation of authentication requirements in GitLab's API endpoints. Users could bypass 2FA restrictions using either a session cookie for GET requests or a previously generated private token for both GET and POST requests. The issue affected all previous GitLab versions until the release of the patched versions (HackerOne Report).

Impact

This vulnerability allowed unauthorized access to group resources that should have been protected by 2FA requirements. Attackers could access and interact with group resources, including projects and their associated data, effectively rendering the 2FA group security setting ineffective (GitLab Issue).

Exploitability

The vulnerability could be exploited by using either a valid session cookie or a previously generated private token to make API requests. While GET requests were possible with session cookies, private tokens enabled both GET and POST requests, allowing for more extensive access to protected resources (HackerOne Report).

Mitigation and workarounds

The vulnerability was patched in GitLab versions 13.1.10, 13.2.8, and 13.3.4. Organizations running affected versions were strongly recommended to upgrade to these patched versions immediately to prevent unauthorized access to group resources (GitLab Release).

Community reactions

The vulnerability was responsibly reported by security researcher xanbanx through GitLab's bug bounty program on HackerOne. GitLab addressed the issue promptly and included the fix in their security release (GitLab Release).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85706CRITICAL10
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
YesYesSep 12, 2026
CVE-2026-87719CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 12, 2026
CVE-2026-75871CRITICAL9.6
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 27, 2026
CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management