CVE-2020-13347 Information
Feb 14, 2021
cve
Description
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor which allows the attacker to run arbitrary commands on Windows host via DOCKER_AUTH_CONFIG build variable.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Reference
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13347.json https://gitlab.com/gitlab-org/gitlab-runner/-/issues/26725 https://hackerone.com/reports/955016
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.1
Share on: