MEDIUM

CVE-2020-10086

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
5.3

Description

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

Summary dbcve.org

GitLab versions 10.4 through 12.8.1 contain a directory traversal vulnerability in a specific endpoint that allows authenticated or unauthenticated attackers to read arbitrary files on the host system by manipulating file paths with traversal sequences (e.g., ../../).

Mitigation

Upgrade GitLab to version 12.8.2 or later. If immediate patching is not feasible, restrict network access to the vulnerable endpoint and implement Web Application Firewall rules to block directory traversal patterns.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

1.33%
Probability of exploitation in next 30 days
69.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE