MEDIUM

CVE-2020-10085

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
5.3

Description

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

Summary dbcve.org

In GitLab versions 12.3.5 through 12.8.1, a specific view was exposing the titles of private merge requests to unauthorized users. This allowed information disclosure of sensitive merge request content that should have been restricted to authorized project members.

Mitigation

Upgrade GitLab to version 12.8.2 or later to patch this information disclosure vulnerability.

EPSS Score

0.93%
Probability of exploitation in next 30 days
59th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE