CVE-2020-10080: Medium severity gitlab vulnerability
Published Mar 13, 2020
·Updated
GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.
Affected Software
2 affected components
GitLab GitLab>=8.3.0<=12.8.1
GitLab GitLab>=8.3.0<=12.8.1
Event History
Mar 13, 2020
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10080?
CVE-2020-10080 has a medium severity level due to the potential information disclosure risk.
2
How do I fix CVE-2020-10080?
To fix CVE-2020-10080, upgrade GitLab to version 12.8.2 or later.
3
What does CVE-2020-10080 affect?
CVE-2020-10080 affects GitLab versions 8.3 through 12.8.1, including both Community and Enterprise editions.
4
Who can exploit CVE-2020-10080?
CVE-2020-10080 can be exploited by non-members of a private group who can access the Contribution Analytics page.
5
What is the main issue with CVE-2020-10080?
The main issue with CVE-2020-10080 is that it allows unauthorized access to sensitive analytics information in private GitLab groups.