CVE Vulnerabilities

CVE-2020-13358

Published: Nov 17, 2020 | Modified: Jul 21, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 13.3.0 (including) 13.3.9 (excluding)
Gitlab Gitlab 13.3.0 (including) 13.3.9 (including)
Gitlab Gitlab 13.4.0 (including) 13.4.5 (excluding)
Gitlab Gitlab 13.5.0 (including) 13.5.2 (excluding)

References