AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-20500

HIGH · CVSS 7.5 EPSS 1.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-05-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-20500
Severity
HIGH
CVSS
7.5
EPSS
1.42%
GitLab

Original NVD Description

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.