CVE-2020-10953: Path Traversal
Published Mar 27, 2020
·Updated
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
Affected Software
1 affected component
GitLab GitLab>=11.7.0<=12.9
Event History
Mar 27, 2020
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10953?
CVE-2020-10953 has a medium severity rating due to its potential for path traversal attacks.
2
How do I fix CVE-2020-10953?
To fix CVE-2020-10953, upgrade GitLab to version 12.9.1 or later.
3
What versions of GitLab are affected by CVE-2020-10953?
CVE-2020-10953 affects GitLab EE versions from 11.7 through 12.9.
4
What is the impact of CVE-2020-10953?
CVE-2020-10953 allows attackers to exploit a path traversal vulnerability, potentially accessing unauthorized files.
5
Is there a workaround for CVE-2020-10953?
There is no official workaround for CVE-2020-10953; upgrading to a safe version is necessary.