First published: Fri Mar 13 2020(Updated: )
GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.6.0<=12.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10084 is classified as a medium severity vulnerability due to potential information disclosure risks.
To mitigate CVE-2020-10084, users should upgrade to GitLab EE version 12.8.2 or later.
CVE-2020-10084 is an information disclosure vulnerability that affects the GitLab EE software.
Users of GitLab EE versions 11.6 through 12.8.1 are affected by CVE-2020-10084.
CVE-2020-10084 could lead to the exposure of a private project namespace if exploited.