CVE-2020-13350 — Cross-Site Request Forgery in Gitlab
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 61.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 17
Latest updateMay 24
Description
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, =13.4.0, <13.4.5,<13.3.9.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
2GHSA▶
GHSA-857m-xj2v-vhp3: CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/res↗2022-05-24
OSV▶
CVE-2020-13350: CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/res↗2020-11-17
📋Vendor Advisories
2GitLab▶
CVE-2020-13350: CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/res↗2020-11-17
Debian▶
CVE-2020-13350: gitlab - CSRF in runner administration page in all versions of GitLab CE/EE allows an att...↗2020