CVE-2020-10085: Medium severity gitlab vulnerability
Published Mar 13, 2020
·Updated
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
Affected Software
2 affected components
GitLab GitLab>=12.3.5<=12.8.1
GitLab GitLab>=12.3.5<=12.8.1
Event History
Mar 13, 2020
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10085?
The severity of CVE-2020-10085 is classified as medium due to the potential for information disclosure.
2
How do I fix CVE-2020-10085?
To fix CVE-2020-10085, update GitLab to version 12.8.2 or later.
3
What types of systems are affected by CVE-2020-10085?
CVE-2020-10085 affects both GitLab Community and Enterprise editions from version 12.3.5 to 12.8.1.
4
What information is disclosed by CVE-2020-10085?
CVE-2020-10085 potentially exposes titles of private merge requests in a specific view.
5
Is CVE-2020-10085 being actively exploited?
As of the latest information, there have been no reports indicating that CVE-2020-10085 is being actively exploited.