CVE-2020-13359Sensitive Information Exposure in Gitlab

Severity
7.6HIGHNVD
EPSS
0.1%
top 75.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateMay 24

Description

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, =13.4, =13.5, <13.5.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:NExploitability: 2.3 | Impact: 4.7

Affected Packages5 packages

NVDgitlab/gitlab12.10.013.3.9+2
debiandebian/gitlab< gitlab 13.3.9-1 (sid)
gitlabgitlab/gitlab
CVEListV5gitlab/gitlab_ce_ee6 versions+5

🔴Vulnerability Details

1
GHSA
GHSA-x995-5r6x-9xh3: The Terraform API in GitLab CE/EE 122022-05-24

📋Vendor Advisories

2
GitLab
CVE-2020-13359: The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to over2020-11-19
Debian
CVE-2020-13359: gitlab - The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL o...2020