CVE-2020-13327: High severity gitlab runner vulnerability
An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-13327.
What is the title of this vulnerability?
The title of this vulnerability is 'Insecure Runner Configuration in Kubernetes Environments'.
Which versions of GitLab Runner are affected by this vulnerability?
All versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, and all versions starting from 13.2.0 before 13.2.10 of GitLab Runner are affected by this vulnerability.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is 7.5 (high).
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [CVE-2020-13327](https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13327.json), [GitLab Runner Issue #26833](https://gitlab.com/gitlab-org/gitlab-runner/-/issues/26833).