MEDIUM
CVE-2020-10978
CVSS
5.3
Description
GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.
Summary dbcve.org
GitLab versions 8.11 through 12.9 contain an information disclosure vulnerability where Issues created in a public project and subsequently moved to a private project remain accessible via Web-UI and GraphQL API to unauthorized users. The system fails to properly enforce access controls after the project visibility change, allowing attackers to read sensitive Issue content that should be private.
Mitigation
Upgrade to GitLab 12.9.1 or later to receive the patch. Alternatively, avoid moving Issues from public to private projects until the upgrade is complete.
EPSS Score
1.17%
Probability of exploitation in next 30 days
65.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.