First published: Wed Apr 08 2020(Updated: )
GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.10.0<=12.9 | |
GitLab | >=11.10.0<=12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10979 has a medium severity rating due to the exposure of restricted CI pipelines metrics.
To mitigate CVE-2020-10979, upgrade GitLab EE/CE versions between 11.10 and 12.9 to version 12.9.1 or later.
The vulnerability could allow unauthorized users to access sensitive metrics related to CI pipelines.
CVE-2020-10979 affects GitLab EE/CE versions from 11.10 to 12.9.
Yes, CVE-2020-10979 affects both GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) versions 11.10 to 12.9.