5
CVSSv2

CVE-2018-20500

Published: 17/05/2019 Updated: 24/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An insecure permissions issue exists in GitLab Community and Enterprise Edition 9.4 and later but prior to 11.4.13, 11.5.x prior to 11.5.6, and 11.6.x prior to 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

Vendor Advisories

Debian Bug report logs - #918086 gitlab: CVE-2018-20488 CVE-2018-20489 CVE-2018-20490 CVE-2018-20491 CVE-2018-20492 CVE-2018-20493 CVE-2018-20494 CVE-2018-20495 CVE-2018-20496 CVE-2018-20497 CVE-2018-20498 CVE-2018-20499 CVE-2018-20500 CVE-2018-20501 CVE-2018-20507 Package: src:gitlab; Maintainer for src:gitlab is Debian Ruby Extras Maint ...