HIGH

CVE-2020-13327

Gitlab Runner 2020-10-22 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments

Summary dbcve.org

GitLab Runner versions 13.2.x before 13.2.10, 13.3.x before 13.3.7, and 13.4.x before 13.4.2 contain an insecure configuration vulnerability when deployed in Kubernetes environments. The HIGH CVSS score of 7.5 indicates the issue could allow attackers to exploit runner configuration weaknesses, potentially leading to unauthorized access to resources or pipeline manipulation.

Mitigation

Upgrade GitLab Runner to version 13.4.2, 13.3.7, 13.2.10 or later in all Kubernetes deployments. Verify runner configurations follow security best practices post-upgrade.

EPSS Score

0.72%
Probability of exploitation in next 30 days
52.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE