
Cloud Vulnerability DB
A community-led vulnerabilities database
A blind Server-Side Request Forgery (SSRF) vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. The vulnerability, identified as CVE-2020-13309, was found in the repository mirroring feature of GitLab. This security issue was reported by security researcher sky003 and was patched in a security release on September 2, 2020 (GitLab Release, CVE Mitre).
The vulnerability stemmed from URL parsing differentials between the GitLab application and Git. An attacker could exploit this by using malformed git repository URLs in the format git://localhost:[port]/[controlled-payload]@[legit-host]/. The issue allowed bypass of SSRF protection mechanisms through specifically crafted repository mirror URLs (HackerOne Report).
The vulnerability allowed malicious users to establish TCP connections with local or internal network resources. While primarily resulting in blind SSRF attacks, attackers could potentially read git output from repository mirror update status through error messages (GitLab Release).
The vulnerability could be exploited by an authenticated user with access to the repository mirroring feature. The attack vector involved creating a mirror with a specially crafted Git repository URL and triggering an update for the mirror (HackerOne Report).
GitLab addressed this vulnerability in versions 13.1.10, 13.2.8, and 13.3.4. Organizations running affected versions are strongly recommended to upgrade to the patched versions immediately (GitLab Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."