MEDIUM

CVE-2020-10978

Gitlab GitLab 2020-04-08 CVSS v3.1
CVSS
5.3

Description

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

Summary dbcve.org

GitLab versions 8.11 through 12.9 contain an information disclosure vulnerability where Issues created in a public project and subsequently moved to a private project remain accessible via Web-UI and GraphQL API to unauthorized users. The system fails to properly enforce access controls after the project visibility change, allowing attackers to read sensitive Issue content that should be private.

Mitigation

Upgrade to GitLab 12.9.1 or later to receive the patch. Alternatively, avoid moving Issues from public to private projects until the upgrade is complete.

EPSS Score

1.17%
Probability of exploitation in next 30 days
65.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE