HIGH

CVE-2020-10976

Gitlab GitLab 2020-04-08 CVSS v3.1
CVSS
7.5

Description

GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.

Summary dbcve.org

GitLab EE/CE versions 8.17 through 12.9 contain an information leakage vulnerability in the merge request widget component. The vulnerability allows unauthorized access to sensitive information when querying the merge request widget, likely due to improper access control or authorization checks in the widget's data retrieval mechanism.

Mitigation

Upgrade GitLab to version 12.9.1 or later. This is a standard patch release that addresses the information disclosure in the merge request widget functionality.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.16%
Probability of exploitation in next 30 days
65.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE