MEDIUM
CVE-2020-10080
CVSS
5.3
Description
GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.
Summary dbcve.org
GitLab versions 8.3 through 12.8.1 had an improper access control vulnerability where non-members could access the Contribution Analytics page of private groups, exposing sensitive collaboration and contribution data to unauthorized users.
Mitigation
Upgrade GitLab to version 12.8.2 or later to patch the authorization bypass. Alternatively, if immediate upgrade is not possible, restrict access to the Contribution Analytics feature until the patch can be applied.
EPSS Score
0.93%
Probability of exploitation in next 30 days
59th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.