MEDIUM

CVE-2020-13351

Gitlab GitLab 2020-11-17 CVSS v3.1
CVSS
6.5

Description

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

Summary dbcve.org

Insufficient permission checks in GitLab's scheduled pipeline API allow authenticated users who can view a project to read sensitive variable names and values from scheduled pipeline configurations through the API, exposing potentially secret credentials.

Mitigation

Upgrade GitLab to version 13.3.9, 13.4.5, or 13.5.2 or later. Until upgraded, avoid storing sensitive variables in scheduled pipelines for projects with untrusted members.

Weakness (CWE)

CWE-276 Incorrect Default Permissions

EPSS Score

1.36%
Probability of exploitation in next 30 days
70.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE