An authorization flaw in the mirroring logic of GitLab CE/EE versions 10.6 and later through 13.0.5 allowed unauthorized users to gain read access to private repositories. The vulnerability is due to improper enforcement of access controls during repository mirroring operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a full Docker-based lab environment to demonstrate and exploit CVE-2020-13277, a logic flaw in GitLab EE that allows arbitrary users to escalate privileges and access private repositories via the repository mirroring feature. The structure includes scripts for generating a cracked license (keygen.sh/ps1, license/license.rb), Dockerfiles for GitLab and the license generator, and automation scripts for running, registering, and stopping the environment. The README.md offers a detailed walkthrough of the exploit scenario, including setup, user creation, repository configuration, and the attack chain. The exploit leverages the ability to mirror a public repository into a group, transfer group ownership to a victim, and then execute a CI pipeline under the victim's privileges, thereby accessing private repository contents. The main attack vector is network-based, exploiting GitLab's internal HTTP endpoints and CI/CD pipeline execution. The repository is a proof-of-concept and does not include weaponized payloads, but demonstrates the full attack chain in a controlled environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.