CVE-2020-13350Cross-Site Request Forgery in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 61.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateMay 24

Description

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, =13.4.0, <13.4.5,<13.3.9.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab13.4.013.4.5+2
debiandebian/gitlab< gitlab 13.3.9-1 (sid)
gitlabgitlab/gitlab
CVEListV5gitlab/gitlab_ce_ee5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-857m-xj2v-vhp3: CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/res2022-05-24
OSV
CVE-2020-13350: CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/res2020-11-17

📋Vendor Advisories

2
GitLab
CVE-2020-13350: CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/res2020-11-17
Debian
CVE-2020-13350: gitlab - CSRF in runner administration page in all versions of GitLab CE/EE allows an att...2020