CVE-2020-10084: Medium severity gitlab vulnerability
Published Mar 13, 2020
·Updated
GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerabilityfeedback endpoint could result in the exposure of a private project namespace
Affected Software
1 affected component
GitLab GitLab>=11.6.0<=12.8.1
Event History
Mar 13, 2020
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10084?
CVE-2020-10084 is classified as a medium severity vulnerability due to potential information disclosure risks.
2
How do I fix CVE-2020-10084?
To mitigate CVE-2020-10084, users should upgrade to GitLab EE version 12.8.2 or later.
3
What type of vulnerability is CVE-2020-10084?
CVE-2020-10084 is an information disclosure vulnerability that affects the GitLab EE software.
4
Who is affected by CVE-2020-10084?
Users of GitLab EE versions 11.6 through 12.8.1 are affected by CVE-2020-10084.
5
What could be exposed due to CVE-2020-10084?
CVE-2020-10084 could lead to the exposure of a private project namespace if exploited.