CVE-2020-7969: High severity GitLab GitLab vulnerability
Published Feb 5, 2020
·Updated
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
Affected Software
3 affected components
GitLab GitLab>=8.0.0<12.5.9
GitLab GitLab>=12.6.0<12.6.6
GitLab GitLab>=12.7.0<=12.7.2
Event History
Feb 5, 2020
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7969?
CVE-2020-7969 is classified as a medium severity vulnerability due to the potential for information disclosure.
2
How do I fix CVE-2020-7969?
To fix CVE-2020-7969, upgrade your GitLab EE instance to version 12.7.3 or later.
3
What versions of GitLab are affected by CVE-2020-7969?
CVE-2020-7969 affects GitLab EE versions from 8.0 through 12.7.2.
4
What type of vulnerability is CVE-2020-7969?
CVE-2020-7969 is an information disclosure vulnerability that allows unauthorized access to sensitive information.
5
Is there a workaround for CVE-2020-7969?
There is no known workaround for CVE-2020-7969; updating to the fixed version is the recommended action.