MEDIUM
CVE-2020-13264
CVSS
5.3
Description
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
Summary dbcve.org
GitLab CE/EE versions 10.3 through 13.0.1 contain an improper authorization flaw where group maintainers can view Kubernetes cluster tokens that should be restricted to higher-privileged users, exposing sensitive credentials.
Mitigation
Upgrade GitLab to version 13.0.2 or later. As a temporary measure, restrict cluster token visibility settings and audit group membership until the upgrade is completed.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
1.08%
Probability of exploitation in next 30 days
63.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.