MEDIUM
CVE-2020-10086
CVSS
5.3
Description
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.
Summary dbcve.org
GitLab versions 10.4 through 12.8.1 contain a directory traversal vulnerability in a specific endpoint that allows authenticated or unauthenticated attackers to read arbitrary files on the host system by manipulating file paths with traversal sequences (e.g., ../../).
Mitigation
Upgrade GitLab to version 12.8.2 or later. If immediate patching is not feasible, restrict network access to the vulnerable endpoint and implement Web Application Firewall rules to block directory traversal patterns.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
1.33%
Probability of exploitation in next 30 days
69.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.