HIGH
CVE-2020-13359
CVSS
7.6
Description
The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
Summary dbcve.org
The Terraform API in GitLab CE/EE versions 12.10+ exposed object storage signed URLs during delete operations, allowing a malicious project maintainer to overwrite Terraform state files and bypass audit and business controls.
Mitigation
Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later to patch this vulnerability.
EPSS Score
0.77%
Probability of exploitation in next 30 days
53.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.