Insecure Runner Configuration in GitLab Runner Affects Kubernetes Deployments
CVE-2020-13327

6MEDIUM

Key Information:

Vendor

Gitlab

Vendor
CVE Published:
22 October 2020

What is CVE-2020-13327?

A configuration issue has been identified in GitLab Runner, which affects multiple versions used within Kubernetes environments. Prior to the fixed versions, configurations may inadvertently expose sensitive data or systems to potential exploitation. It is recommended for users to upgrade to the specified secure versions to mitigate any related risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GitLab Runner >=13.4.0, <13.4.2 < 13.4.0, 13.4.2

GitLab Runner >=13.3.0, <13.3.7 < 13.3.0, 13.3.7

GitLab Runner >=13.2.0, <13.2.10 < 13.2.0, 13.2.10

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by the GitLab team
.