HIGH

CVE-2020-10953

Gitlab GitLab 2020-03-27 CVSS v3.1
CVSS
7.5

Description

In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

Summary dbcve.org

GitLab EE versions 11.7 through 12.9 contain a path traversal vulnerability in the NPM package management feature, allowing attackers to access files outside the intended directory through specially crafted package requests.

Mitigation

Upgrade GitLab to version 12.9.1 or later to patch the path traversal vulnerability in the NPM feature.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

1.64%
Probability of exploitation in next 30 days
75.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE