CVE-2020-10090: Infoleak
Published Mar 13, 2020
·Updated
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
Affected Software
2 affected components
GitLab GitLab>=11.7.0<=12.8.1
GitLab GitLab>=11.7.0<=12.8.1
Event History
Mar 13, 2020
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10090?
CVE-2020-10090 has been classified as a medium severity vulnerability due to the potential for information disclosure.
2
How do I fix CVE-2020-10090?
To remediate CVE-2020-10090, you should upgrade to GitLab version 12.8.2 or later.
3
What type of information is disclosed in CVE-2020-10090?
CVE-2020-10090 discloses group epic information under certain group conditions which could expose sensitive project details.
4
Which versions of GitLab are affected by CVE-2020-10090?
CVE-2020-10090 affects GitLab versions from 11.7.0 to 12.8.1.
5
Is CVE-2020-10090 a critical vulnerability?
CVE-2020-10090 is not classified as critical, but it still poses a risk due to the potential unauthorized access to group information.