Lucene search

K

Runner Security Vulnerabilities

cve
cve

CVE-2020-13295

For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

8.8CVSS

8.4AI Score

0.002EPSS

2020-08-10 02:15 PM
29
cve
cve

CVE-2020-13327

An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments

7.5CVSS

7.2AI Score

0.001EPSS

2020-10-22 09:15 PM
27
cve
cve

CVE-2021-39947

In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs

7.5CVSS

7.2AI Score

0.001EPSS

2022-06-06 05:15 PM
32
2
cve
cve

CVE-2022-2251

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other ...

8CVSS

7.5AI Score

0.002EPSS

2023-01-17 09:15 PM
76
cve
cve

CVE-2022-39321

GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the docker cli directly in order to run job containers, service containers, or container actions. A bug in the logic for how the environment is encoded into these docker commands was ...

9.9CVSS

9.7AI Score

0.001EPSS

2022-10-25 05:15 PM
36
6