First published: Thu May 07 2020(Updated: )
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.8.0<12.8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12448 has a medium severity rating, indicating a moderate level of risk to users of GitLab EE.
To address CVE-2020-12448, you should upgrade your GitLab EE installation to version 12.8.10 or later.
CVE-2020-12448 is a vulnerability that allows the exposure of sensitive information to unauthorized actors.
CVE-2020-12448 affects GitLab EE versions from 12.8.0 up to but not including 12.8.10.
Users of GitLab EE versions 12.8 and later are impacted by CVE-2020-12448 if they have not updated to the patched version.