MEDIUM
CVE-2020-13310
CVSS
6.5
Description
A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.
Summary dbcve.org
A denial of service vulnerability exists in GitLab Runner versions prior to 13.1.3, 13.2.3, and 13.3.1. An attacker can send specially crafted malformed queries to the gitlab-runner process, causing it to crash and become unavailable.
Mitigation
Upgrade GitLab Runner to version 13.1.3, 13.2.3, 13.3.1 or later to patch the vulnerability. If immediate upgrade is not possible, restrict network access to the runner's API endpoints.
EPSS Score
1.65%
Probability of exploitation in next 30 days
75.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.