MEDIUM

CVE-2020-13358

Gitlab GitLab 2020-11-17 CVSS v3.1
CVSS
5.5

Description

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

Summary dbcve.org

GitLab's internal Kubernetes agent API has an access control flaw that allows unauthorized access to private projects. The vulnerability exists in the authentication/authorization logic of the Kubernetes agent feature, enabling attackers to potentially read private project data without proper credentials.

Mitigation

Upgrade GitLab to version 13.4.5, 13.3.9, 13.5.2 or later to patch the vulnerability. Alternatively, disable the Kubernetes agent feature if not needed until upgrade is possible.

EPSS Score

0.33%
Probability of exploitation in next 30 days
25.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE