
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1, identified as CVE-2020-13310. The vulnerability allowed attackers to crash the gitlab-runner process through malformed queries, leading to a denial of service condition (CVE Details, NVD).
The vulnerability has been assigned a CVSS v3.1 score of 6.5 (Medium) and CVSS v2.0 score of 4.0 (Medium). The issue specifically affects the GitLab runner process handling of queries, where malformed input could trigger a crash condition (NVD).
When successfully exploited, this vulnerability results in a denial of service condition by causing the gitlab-runner process to crash, potentially disrupting CI/CD operations (GitLab Security Release).
The vulnerability can be triggered by sending malformed queries to the GitLab runner process. The attack vector requires the ability to interact with the GitLab runner instance (GitLab Security Release).
Users are strongly recommended to upgrade to GitLab runner versions 13.1.3, 13.2.3, or 13.3.1 or later to address this vulnerability. These versions contain the necessary security fixes to prevent the denial of service condition (GitLab Security Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."