CVE-2018-20500: High severity gitlab vulnerability
An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20500?
CVE-2018-20500 has been classified as a high severity vulnerability due to its potential to expose sensitive tokens.
How do I fix CVE-2018-20500?
To fix CVE-2018-20500, upgrade your GitLab instance to version 11.6.1 or later.
What vulnerabilities are associated with CVE-2018-20500?
CVE-2018-20500 is associated with insecure permissions that affect the runner registration token in GitLab.
Which versions of GitLab are affected by CVE-2018-20500?
CVE-2018-20500 affects GitLab Community and Enterprise Editions from version 9.4 up to but not including 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
Who is at risk from CVE-2018-20500?
Users of GitLab who have maintainers that may leave the organization are at risk from CVE-2018-20500.