MEDIUM
CVE-2020-10085
CVSS
5.3
Description
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
Summary dbcve.org
In GitLab versions 12.3.5 through 12.8.1, a specific view was exposing the titles of private merge requests to unauthorized users. This allowed information disclosure of sensitive merge request content that should have been restricted to authorized project members.
Mitigation
Upgrade GitLab to version 12.8.2 or later to patch this information disclosure vulnerability.
EPSS Score
0.93%
Probability of exploitation in next 30 days
59th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.