CVE-2020-13327
Description
An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments
Summary dbcve.org
GitLab Runner versions 13.2.x before 13.2.10, 13.3.x before 13.3.7, and 13.4.x before 13.4.2 contain an insecure configuration vulnerability when deployed in Kubernetes environments. The HIGH CVSS score of 7.5 indicates the issue could allow attackers to exploit runner configuration weaknesses, potentially leading to unauthorized access to resources or pipeline manipulation.
Mitigation
Upgrade GitLab Runner to version 13.4.2, 13.3.7, 13.2.10 or later in all Kubernetes deployments. Verify runner configurations follow security best practices post-upgrade.