8.8
CVSSv3

CVE-2020-13295

Published: 10/08/2020 Updated: 12/08/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

For GitLab Runner prior to 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab runner

Vendor Advisories

Debian Bug report logs - #985377 CVE-2020-13327 Package: src:gitlab-ci-multi-runner; Maintainer for src:gitlab-ci-multi-runner is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 16 Mar 2021 20:06:01 UTC Severity: grave Tags: security Reply or subscribe to this bu ...