HIGH
CVE-2020-10953
CVSS
7.5
Description
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
Summary dbcve.org
GitLab EE versions 11.7 through 12.9 contain a path traversal vulnerability in the NPM package management feature, allowing attackers to access files outside the intended directory through specially crafted package requests.
Mitigation
Upgrade GitLab to version 12.9.1 or later to patch the path traversal vulnerability in the NPM feature.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
1.64%
Probability of exploitation in next 30 days
75.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.