PT-2020-13436 · Gitlab · Gitlab Runner+1

Published

2020-08-10

·

Updated

2024-03-06

·

CVE-2020-13295

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab Runner versions prior to 13.0.12 GitLab Runner versions prior to 13.1.6 GitLab Runner versions prior to 13.2.3
Description The issue allows for Server-Side Request Forgery (SSRF) by replacing dockerd with a malicious server, making the Shared Runner susceptible.
Recommendations For versions prior to 13.0.12, update to version 13.0.12 or later. For versions prior to 13.1.6, update to version 13.1.6 or later. For versions prior to 13.2.3, update to version 13.2.3 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BIT-GITLAB-RUNNER-2020-13295
CVE-2020-13295

Affected Products

Gitlab
Gitlab Runner