MEDIUM
CVE-2020-10084
CVSS
5.3
Description
GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace
Summary dbcve.org
GitLab EE versions 11.6 through 12.8.1 contain an information disclosure vulnerability in the vulnerability_feedback endpoint. By sending a specially crafted request, an attacker can access the namespace name of private projects they should not have visibility into.
Mitigation
Upgrade GitLab EE to version 12.8.2 or later. As this is an information disclosure with low CVSS impact, prioritize upgrade based on existing change management schedules.
EPSS Score
0.91%
Probability of exploitation in next 30 days
58.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.