First published: Fri Mar 27 2020(Updated: )
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.1.0<12.9.1 | |
GitLab | >=11.1.0<12.9.1 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10955 is classified as a high severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2020-10955, upgrade GitLab to version 12.9.1 or later.
CVE-2020-10955 affects GitLab Community Edition and Enterprise Edition versions from 11.1 to 12.9.1.
CVE-2020-10955 is a parameter tampering vulnerability that allows unauthorized access to certain folder content.
Yes, CVE-2020-10955 impacts GitLab installations on Debian Linux version 10.0 if they are within the affected version range.