HIGH

CVE-2020-13295

Gitlab Runner 2020-08-10 CVSS v3.1
CVSS
8.8

Description

For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

Summary dbcve.org

GitLab Runner versions before 13.0.12, 13.1.6, and 13.2.3 contain an SSRF vulnerability where an attacker who can replace the dockerd daemon with a malicious server can cause the Shared Runner to make unintended network requests to attacker-controlled endpoints.

Mitigation

Upgrade GitLab Runner to version 13.0.12, 13.1.6, 13.2.3 or later. Additionally, ensure proper access controls and integrity verification for the dockerd binary to prevent unauthorized replacement.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

1.17%
Probability of exploitation in next 30 days
66th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE