{"id":"CVE-2020-13353","aliases":["GHSA-mmmm-chjf-jmvw"],"url":"https://o3.security/vulnerability/CVE-2020-13353","summary":"Gitaly Insufficient Session Expiration vulnerability","details":"When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.","published":"2020-11-17T01:15:13.310Z","modified":"2026-07-29T08:20:23.479261Z","cvss":{"score":3.2,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"gitaly","fixedVersion":"13.3.9"},{"ecosystem":"RubyGems","name":"gitaly","fixedVersion":"13.4.5"},{"ecosystem":"RubyGems","name":"gitaly","fixedVersion":"13.5.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13353.json"},{"type":"REPORT","url":"https://gitlab.com/gitlab-org/gitaly/-/issues/2882"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-29T08:20:23.479261Z"}}