HIGH

CVE-2020-6833

Gitlab GitLab 2020-02-05 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

Summary dbcve.org

A request smuggling vulnerability in GitLab Workhorse (EE 11.3+) allows attackers to bypass security controls and access sensitive files/packages that should be protected. The flaw exploits how GitLab Workhorse handles ambiguous HTTP requests, potentially enabling unauthorized disclosure of internal packages or files accessible through the GitLab instance.

Mitigation

Upgrade GitLab EE to the patched version addressing CVE-2020-6833; review and audit access logs for suspicious request patterns indicative of smuggling attempts.

EPSS Score

1.17%
Probability of exploitation in next 30 days
66.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE