Description
The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
None
Affected products
- gitlab / GitLab CE/EE>=12.10 – >=12.10
- gitlab / GitLab CE/EE<13.3.9 – <13.3.9
- gitlab / GitLab CE/EE>=13.4 – >=13.4
- gitlab / GitLab CE/EE<13.4.5 – <13.4.5
- gitlab / GitLab CE/EE>=13.5 – >=13.5
- gitlab / GitLab CE/EE<13.5.2 – <13.5.2