HIGH

CVE-2020-7966

Gitlab GitLab 2020-02-05 CVSS v3.1
CVSS
7.5

Description

GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

Summary dbcve.org

Directory Traversal vulnerability in GitLab EE versions 11.11 through 12.7.2 allows attackers to access files outside the web root directory via specially crafted requests containing traversal sequences.

Mitigation

Upgrade GitLab EE to version 12.7.3 or later to resolve the directory traversal vulnerability.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

1.65%
Probability of exploitation in next 30 days
75.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE