CVE-2020-13350: CSRF
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13350?
CVE-2020-13350 is classified as a medium severity vulnerability due to the potential impact on GitLab administration.
How do I fix CVE-2020-13350?
To address CVE-2020-13350, upgrade GitLab to version 13.5.2 or above, or 13.4.5 or above.
What is the nature of CVE-2020-13350?
CVE-2020-13350 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the runner administration page of GitLab.
Which versions of GitLab are affected by CVE-2020-13350?
CVE-2020-13350 affects GitLab versions 13.5.0 to 13.5.1, 13.4.0 to 13.4.4, and all versions before 13.3.9.
Who can exploit CVE-2020-13350?
An attacker must be able to target GitLab instance administrators to successfully exploit CVE-2020-13350.