PT-2020-13500 · Gitlab+1 · Gitlab Ce/Ee+2

Published

2020-11-18

·

Updated

2024-03-06

·

CVE-2020-13359

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 12.10 through 13.3.8 GitLab CE/EE versions 13.4 through 13.4.4 GitLab CE/EE versions 13.5 through 13.5.1
Description The Terraform API in GitLab CE/EE exposed the object storage signed URL on the delete operation, allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls.
Recommendations For GitLab CE/EE versions 12.10 through 13.3.8, update to version 13.3.9 or later. For GitLab CE/EE versions 13.4 through 13.4.4, update to version 13.4.5 or later. For GitLab CE/EE versions 13.5 through 13.5.1, update to version 13.5.2 or later.

Fix

Related Identifiers

BIT-GITLAB-2020-13359
CVE-2020-13359

Affected Products

Gitlab
Gitlab Ce/Ee
Terraform