CVE-2020-11506
Description
An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.
Summary dbcve.org
This is a request smuggling vulnerability in GitLab's Workhorse component (the reverse proxy that handles file uploads and other operations). The flaw allows attackers to bypass Workhorse security controls and potentially upload malicious job artifacts or access sensitive files on the GitLab server. The vulnerability stems from how GitLab handles proxied requests.
Mitigation
Upgrade GitLab to version 12.9.3 or later to patch the Workhorse bypass vulnerability. Organizations running affected versions (10.7.0 through 12.9.2) should prioritize this upgrade given the high CVSS score and potential for sensitive data exposure.