CVE-2020-6833: High severity GitLab GitLab vulnerability
Published Feb 5, 2020
·Updated
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
Affected Software
3 affected components
GitLab GitLab>=11.3.0<12.5.9
GitLab GitLab>=12.6.0<12.6.6
GitLab GitLab>=12.7.2<12.7.4
Event History
Feb 5, 2020
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-6833?
CVE-2020-6833 has been classified as a medium severity vulnerability due to its potential for package and file disclosure.
2
How do I fix CVE-2020-6833?
To remediate CVE-2020-6833, upgrade GitLab to version 12.7.4 or later or apply the recommended security patches.
3
What versions of GitLab are affected by CVE-2020-6833?
CVE-2020-6833 affects GitLab EE versions starting from 11.3.0 to 12.7.4, excluding 12.7.4.
4
What is the impact of CVE-2020-6833?
CVE-2020-6833 can allow attackers to bypass GitLab Workhorse and potentially disclose sensitive packages and files.
5
Is CVE-2020-6833 specific to GitLab EE?
Yes, CVE-2020-6833 specifically impacts GitLab Enterprise Edition.