For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"vendor_product": "gitlab:runner",
"extracted_events": [
{
"introduced": "1.0"
},
{
"fixed": "13.0.12"
},
{
"introduced": "1.0"
},
{
"fixed": "13.0.12"
},
{
"introduced": "13.1"
},
{
"fixed": "13.1.6"
},
{
"introduced": "13.1"
},
{
"fixed": "13.1.6"
}
],
"cpes": [
"cpe:2.3:a:gitlab:runner:*:*:*:*:*:*:*:*"
]
}
]
}