MEDIUM
CVE-2020-10977
CVSS
5.5
Description
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
42.74%
Probability of exploitation in next 30 days
98.7th percentile
References
http://packetstormsecurity.com/files/160441/GitLab-File-Read-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/
Vendor Advisory
https://about.gitlab.com/releases/categories/releases/
Release Notes, Vendor Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.