MEDIUM

CVE-2020-10080

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
5.3

Description

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

Summary dbcve.org

GitLab versions 8.3 through 12.8.1 had an improper access control vulnerability where non-members could access the Contribution Analytics page of private groups, exposing sensitive collaboration and contribution data to unauthorized users.

Mitigation

Upgrade GitLab to version 12.8.2 or later to patch the authorization bypass. Alternatively, if immediate upgrade is not possible, restrict access to the Contribution Analytics feature until the patch can be applied.

EPSS Score

0.93%
Probability of exploitation in next 30 days
59th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE