MEDIUM
CVE-2020-13358
CVSS
5.5
Description
A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.
Summary dbcve.org
GitLab's internal Kubernetes agent API has an access control flaw that allows unauthorized access to private projects. The vulnerability exists in the authentication/authorization logic of the Kubernetes agent feature, enabling attackers to potentially read private project data without proper credentials.
Mitigation
Upgrade GitLab to version 13.4.5, 13.3.9, 13.5.2 or later to patch the vulnerability. Alternatively, disable the Kubernetes agent feature if not needed until upgrade is possible.
EPSS Score
0.33%
Probability of exploitation in next 30 days
25.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.