HIGH

CVE-2020-11505

Gitlab GitLab 2020-04-22 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.

Summary dbcve.org

A request smuggling vulnerability in GitLab Workhorse allows attackers to bypass security controls and access sensitive NuGet packages and files that should be restricted, leading to information disclosure.

Mitigation

Upgrade GitLab to version 12.7.9, 12.8.9, 12.9.3 or later to patch the Workhorse bypass vulnerability.

Weakness (CWE)

CWE-444

EPSS Score

1.17%
Probability of exploitation in next 30 days
66.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE