CVE-2018-20500
published 2019-05-17CVE-2018-20500: An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.42%
69.6th percentile
An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 11.5.6+dfsg-1 (sid) | gitlab 11.5.6+dfsg-1 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | >= 11.5.0 < 11.5.6 | 11.5.6 |
| gitlab | gitlab | >= 11.6.0 < 11.6.1 | 11.6.1 |
| gitlab | gitlab | >= 9.4.0 < 11.4.13 | 11.4.13 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
CVE-2018-20500: An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11
vendor_gitlab·2019-05-17·CVSS 7.5
CVE-2018-20500 [HIGH] CWE-732 CVE-2018-20500: An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11
CVE-2018-20500: An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.
Debian
CVE-2018-20500: gitlab - An insecure permissions issue was discovered in GitLab Community and Enterprise ...
vendor_debian·2018·CVSS 7.5
CVE-2018-20500 [HIGH] CVE-2018-20500: gitlab - An insecure permissions issue was discovered in GitLab Community and Enterprise ...
An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.
Scope: local
sid: resolved (fixed in 11.5.6+dfsg-1)
GHSA
GHSA-fp7j-v353-cf72: An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9
ghsa_unreviewed·2022-05-24
CVE-2018-20500 [HIGH] GHSA-fp7j-v353-cf72: An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9
An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-17
Published