MEDIUM
CVE-2020-13351
CVSS
6.5
Description
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.
Summary dbcve.org
Insufficient permission checks in GitLab's scheduled pipeline API allow authenticated users who can view a project to read sensitive variable names and values from scheduled pipeline configurations through the API, exposing potentially secret credentials.
Mitigation
Upgrade GitLab to version 13.3.9, 13.4.5, or 13.5.2 or later. Until upgraded, avoid storing sensitive variables in scheduled pipelines for projects with untrusted members.
Weakness (CWE)
CWE-276
Incorrect Default Permissions
EPSS Score
1.36%
Probability of exploitation in next 30 days
70.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.