First published: Fri Mar 13 2020(Updated: )
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.3.5<=12.8.1 | |
GitLab | >=12.3.5<=12.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-10085 is classified as medium due to the potential for information disclosure.
To fix CVE-2020-10085, update GitLab to version 12.8.2 or later.
CVE-2020-10085 affects both GitLab Community and Enterprise editions from version 12.3.5 to 12.8.1.
CVE-2020-10085 potentially exposes titles of private merge requests in a specific view.
As of the latest information, there have been no reports indicating that CVE-2020-10085 is being actively exploited.