First published: Fri Mar 27 2020(Updated: )
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.7.0<=12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10953 has a medium severity rating due to its potential for path traversal attacks.
To fix CVE-2020-10953, upgrade GitLab to version 12.9.1 or later.
CVE-2020-10953 affects GitLab EE versions from 11.7 through 12.9.
CVE-2020-10953 allows attackers to exploit a path traversal vulnerability, potentially accessing unauthorized files.
There is no official workaround for CVE-2020-10953; upgrading to a safe version is necessary.