HIGH
CVE-2020-13295
CVSS
8.8
Description
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
Summary dbcve.org
GitLab Runner versions before 13.0.12, 13.1.6, and 13.2.3 contain an SSRF vulnerability where an attacker who can replace the dockerd daemon with a malicious server can cause the Shared Runner to make unintended network requests to attacker-controlled endpoints.
Mitigation
Upgrade GitLab Runner to version 13.0.12, 13.1.6, 13.2.3 or later. Additionally, ensure proper access controls and integrity verification for the dockerd binary to prevent unauthorized replacement.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
1.17%
Probability of exploitation in next 30 days
66th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.