CVE-2020-13295: SSRF
Published Aug 10, 2020
·Updated
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
Affected Software
3 affected components
GitLab Runner>=1.0<13.0.12
GitLab Runner>=13.1<13.1.6
GitLab Runner>=13.2<13.2.3
Event History
Aug 10, 2020
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this GitLab Runner vulnerability?
The vulnerability ID for this GitLab Runner vulnerability is CVE-2020-13295.
2
What is the severity of CVE-2020-13295?
The severity of CVE-2020-13295 is high with a severity value of 8.8.
3
Which versions of GitLab Runner are affected by CVE-2020-13295?
GitLab Runner versions before 13.0.12, 13.1.6, 13.2.3 are affected by CVE-2020-13295.
4
What is the vulnerability description of CVE-2020-13295?
CVE-2020-13295 is a vulnerability in GitLab Runner where the Shared Runner is susceptible to SSRF by replacing dockerd with a malicious server.
5
How can I fix CVE-2020-13295?
To fix CVE-2020-13295, update GitLab Runner to version 13.0.12, 13.1.6, or 13.2.3 or later.