AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-13344

MEDIUM · CVSS 5.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-10-08 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-13344
Severity
MEDIUM
CVSS
5.7
EPSS
0.34%
GitLab

Original NVD Description

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis