MEDIUM

CVE-2020-13264

Gitlab GitLab 2020-06-19 CVSS v3.1
CVSS
5.3

Description

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

Summary dbcve.org

GitLab CE/EE versions 10.3 through 13.0.1 contain an improper authorization flaw where group maintainers can view Kubernetes cluster tokens that should be restricted to higher-privileged users, exposing sensitive credentials.

Mitigation

Upgrade GitLab to version 13.0.2 or later. As a temporary measure, restrict cluster token visibility settings and audit group membership until the upgrade is completed.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE