First published: Fri Mar 13 2020(Updated: )
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.7.0<=12.8.1 | |
GitLab | >=11.7.0<=12.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10090 has been classified as a medium severity vulnerability due to the potential for information disclosure.
To remediate CVE-2020-10090, you should upgrade to GitLab version 12.8.2 or later.
CVE-2020-10090 discloses group epic information under certain group conditions which could expose sensitive project details.
CVE-2020-10090 affects GitLab versions from 11.7.0 to 12.8.1.
CVE-2020-10090 is not classified as critical, but it still poses a risk due to the potential unauthorized access to group information.