MEDIUM
CVE-2020-10955
CVSS
6.5
Description
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
Summary dbcve.org
GitLab EE/CE versions 11.1 through 12.9 contain an Insecure Direct Object Reference (IDOR) vulnerability in the upload feature. Through parameter tampering, an unauthenticated or unauthorized user can manipulate upload parameters to access and read content stored in specific folders they should not have access to.
Mitigation
Upgrade GitLab to version 12.9.1 or later to patch the vulnerable upload feature. Verify that unauthorized users can no longer access restricted folders after upgrading.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
1.03%
Probability of exploitation in next 30 days
62.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.