HIGH
CVE-2020-6833
CVSS
7.5
Description
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
Summary dbcve.org
A request smuggling vulnerability in GitLab Workhorse (EE 11.3+) allows attackers to bypass security controls and access sensitive files/packages that should be protected. The flaw exploits how GitLab Workhorse handles ambiguous HTTP requests, potentially enabling unauthorized disclosure of internal packages or files accessible through the GitLab instance.
Mitigation
Upgrade GitLab EE to the patched version addressing CVE-2020-6833; review and audit access logs for suspicious request patterns indicative of smuggling attempts.
EPSS Score
1.17%
Probability of exploitation in next 30 days
66.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.