MEDIUM

CVE-2020-10084

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
5.3

Description

GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace

Summary dbcve.org

GitLab EE versions 11.6 through 12.8.1 contain an information disclosure vulnerability in the vulnerability_feedback endpoint. By sending a specially crafted request, an attacker can access the namespace name of private projects they should not have visibility into.

Mitigation

Upgrade GitLab EE to version 12.8.2 or later. As this is an information disclosure with low CVSS impact, prioritize upgrade based on existing change management schedules.

EPSS Score

0.91%
Probability of exploitation in next 30 days
58.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE