HIGH
CVE-2020-7966
CVSS
7.5
Description
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
Summary dbcve.org
Directory Traversal vulnerability in GitLab EE versions 11.11 through 12.7.2 allows attackers to access files outside the web root directory via specially crafted requests containing traversal sequences.
Mitigation
Upgrade GitLab EE to version 12.7.3 or later to resolve the directory traversal vulnerability.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
1.65%
Probability of exploitation in next 30 days
75.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.