MEDIUM
CVE-2020-10090
CVSS
5.3
Description
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
Summary dbcve.org
GitLab versions 11.7 through 12.8.1 contain an information disclosure vulnerability where group epic information was unintentionally disclosed under certain group conditions. The vulnerability allows unauthorized access to sensitive metadata about group epics that should have been restricted based on user permissions or group visibility settings.
Mitigation
Upgrade GitLab to version 12.8.2 or later to patch the information disclosure vulnerability. Verify group permission configurations after upgrading to ensure epic data is properly restricted.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
0.93%
Probability of exploitation in next 30 days
59th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.