HIGH
CVE-2020-10976
CVSS
7.5
Description
GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.
Summary dbcve.org
GitLab EE/CE versions 8.17 through 12.9 contain an information leakage vulnerability in the merge request widget component. The vulnerability allows unauthorized access to sensitive information when querying the merge request widget, likely due to improper access control or authorization checks in the widget's data retrieval mechanism.
Mitigation
Upgrade GitLab to version 12.9.1 or later. This is a standard patch release that addresses the information disclosure in the merge request widget functionality.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
1.16%
Probability of exploitation in next 30 days
65.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.