First published: Mon Jan 13 2020(Updated: )
An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.9.0<=12.6.1 | |
GitLab | >=8.9.0<=12.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6832 has been classified as a medium-severity vulnerability.
To resolve CVE-2020-6832, upgrade your GitLab Enterprise Edition to version 12.6.2 or later.
CVE-2020-6832 affects GitLab Enterprise Edition versions from 8.9.0 to 12.6.1 and GitLab Community Edition in the same version range.
CVE-2020-6832 is a data exposure vulnerability that allows unauthorized access to issues from private projects.
CVE-2020-6832 is only present in GitLab installations running the vulnerable versions as specified in the affected software section.