CVE-2020-10975: Medium severity gitlab vulnerability
Published Apr 8, 2020
·Updated
GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.
Affected Software
2 affected components
GitLab GitLab>=10.8.0<=12.9
GitLab GitLab>=10.8.0<=12.9
Event History
Apr 8, 2020
CVE Published
via MITRE·06:11 PM
Data Sourced
via MITRE·06:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10975?
CVE-2020-10975 has a medium severity rating as it involves unauthorized information exposure.
2
How do I fix CVE-2020-10975?
To address CVE-2020-10975, update GitLab to version 12.9.1 or later.
3
What versions are affected by CVE-2020-10975?
CVE-2020-10975 affects GitLab EE/CE versions from 10.8 to 12.9.
4
What type of information is leaked in CVE-2020-10975?
CVE-2020-10975 leaks vulnerability metadata and comments to unauthorized users.
5
Is CVE-2020-10975 present in both community and enterprise editions of GitLab?
Yes, CVE-2020-10975 affects both GitLab Community Edition and Enterprise Edition.