HIGH

CVE-2020-13318

Gitlab GitLab 2020-09-14 CVSS v3.1
CVSS
7.3

Description

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

Summary dbcve.org

GitLab's EKS integration contained a vulnerability allowing cross-account assume role attacks. This flaw in the AWS integration meant that an attacker with certain access could potentially assume IAM roles in other AWS accounts through the GitLab EKS integration feature.

Mitigation

Upgrade GitLab to version 13.0.12, 13.1.10, 13.2.8, or 13.3.4 or later to remediate the vulnerability.

EPSS Score

0.99%
Probability of exploitation in next 30 days
60.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE