CVE-2020-12448: Path Traversal
Published May 7, 2020
·Updated
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
Affected Software
1 affected component
GitLab GitLab>=12.8.0<12.8.10
Event History
May 7, 2020
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12448?
CVE-2020-12448 has a medium severity rating, indicating a moderate level of risk to users of GitLab EE.
2
How do I fix CVE-2020-12448?
To address CVE-2020-12448, you should upgrade your GitLab EE installation to version 12.8.10 or later.
3
What type of vulnerability is CVE-2020-12448?
CVE-2020-12448 is a vulnerability that allows the exposure of sensitive information to unauthorized actors.
4
Which versions of GitLab are affected by CVE-2020-12448?
CVE-2020-12448 affects GitLab EE versions from 12.8.0 up to but not including 12.8.10.
5
Who is impacted by CVE-2020-12448?
Users of GitLab EE versions 12.8 and later are impacted by CVE-2020-12448 if they have not updated to the patched version.