MEDIUM

CVE-2020-10090

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
5.3

Description

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

Summary dbcve.org

GitLab versions 11.7 through 12.8.1 contain an information disclosure vulnerability where group epic information was unintentionally disclosed under certain group conditions. The vulnerability allows unauthorized access to sensitive metadata about group epics that should have been restricted based on user permissions or group visibility settings.

Mitigation

Upgrade GitLab to version 12.8.2 or later to patch the information disclosure vulnerability. Verify group permission configurations after upgrading to ensure epic data is properly restricted.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

0.93%
Probability of exploitation in next 30 days
59th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE