CVE-2020-13309
GitLab vulnerability analysis and mitigation

Overview

A blind Server-Side Request Forgery (SSRF) vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. The vulnerability, identified as CVE-2020-13309, was found in the repository mirroring feature of GitLab. This security issue was reported by security researcher sky003 and was patched in a security release on September 2, 2020 (GitLab Release, CVE Mitre).

Technical details

The vulnerability stemmed from URL parsing differentials between the GitLab application and Git. An attacker could exploit this by using malformed git repository URLs in the format git://localhost:[port]/[controlled-payload]@[legit-host]/. The issue allowed bypass of SSRF protection mechanisms through specifically crafted repository mirror URLs (HackerOne Report).

Impact

The vulnerability allowed malicious users to establish TCP connections with local or internal network resources. While primarily resulting in blind SSRF attacks, attackers could potentially read git output from repository mirror update status through error messages (GitLab Release).

Exploitability

The vulnerability could be exploited by an authenticated user with access to the repository mirroring feature. The attack vector involved creating a mirror with a specially crafted Git repository URL and triggering an update for the mirror (HackerOne Report).

Mitigation and workarounds

GitLab addressed this vulnerability in versions 13.1.10, 13.2.8, and 13.3.4. Organizations running affected versions are strongly recommended to upgrade to the patched versions immediately (GitLab Release).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19478CRITICAL9.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 17, 2026
CVE-2026-10053HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 23, 2026
CVE-2026-19650HIGH7.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 17, 2026
CVE-2026-6821MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 12, 2026
CVE-2026-4879MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management