HIGH
CVE-2020-11505
CVSS
7.5
Description
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.
Summary dbcve.org
A request smuggling vulnerability in GitLab Workhorse allows attackers to bypass security controls and access sensitive NuGet packages and files that should be restricted, leading to information disclosure.
Mitigation
Upgrade GitLab to version 12.7.9, 12.8.9, 12.9.3 or later to patch the Workhorse bypass vulnerability.
Weakness (CWE)
CWE-444
EPSS Score
1.17%
Probability of exploitation in next 30 days
66.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.