HIGH

CVE-2020-13359

Gitlab GitLab 2020-11-19 CVSS v3.1
CVSS
7.6

Description

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Summary dbcve.org

The Terraform API in GitLab CE/EE versions 12.10+ exposed object storage signed URLs during delete operations, allowing a malicious project maintainer to overwrite Terraform state files and bypass audit and business controls.

Mitigation

Upgrade GitLab to version 13.3.9, 13.4.5, 13.5.2 or later to patch this vulnerability.

EPSS Score

0.77%
Probability of exploitation in next 30 days
53.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE