MEDIUM

CVE-2020-10955

Gitlab GitLab 2020-03-27 CVSS v3.1
CVSS
6.5

Description

GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

Summary dbcve.org

GitLab EE/CE versions 11.1 through 12.9 contain an Insecure Direct Object Reference (IDOR) vulnerability in the upload feature. Through parameter tampering, an unauthenticated or unauthorized user can manipulate upload parameters to access and read content stored in specific folders they should not have access to.

Mitigation

Upgrade GitLab to version 12.9.1 or later to patch the vulnerable upload feature. Verify that unauthorized users can no longer access restricted folders after upgrading.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

1.03%
Probability of exploitation in next 30 days
62.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE