CVE-2020-13347 — Path Traversal in Gitlab
Severity
9.1CRITICALNVD
EPSS
1.1%
top 21.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 7
Latest updateMay 24
Description
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG build variable.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-6x9x-gp76-v665: A command injection vulnerability was discovered in Gitlab runner versions prior to 13↗2022-05-24
OSV▶
CVE-2020-13347: A command injection vulnerability was discovered in Gitlab runner versions prior to 13↗2020-10-07
CVEList▶
CVE-2020-13347: A command injection vulnerability was discovered in Gitlab runner versions prior to 13↗2020-10-07
📋Vendor Advisories
1GitLab▶
CVE-2020-13347: A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Wind↗2020-10-07