CVE-2020-7972: High severity GitLab GitLab vulnerability
Published Feb 5, 2020
·Updated
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
Affected Software
3 affected components
GitLab GitLab>=12.0<12.5.9
GitLab GitLab>=12.6.0<12.6.6
GitLab GitLab>=12.7.0<12.7.4
Event History
Feb 5, 2020
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7972?
CVE-2020-7972 is considered a high severity vulnerability due to its potential for exploitation via insecure permissions.
2
How do I fix CVE-2020-7972?
To remediate CVE-2020-7972, upgrade your GitLab instance to version 12.7.4 or later.
3
Which versions of GitLab are affected by CVE-2020-7972?
CVE-2020-7972 affects GitLab Enterprise editions from versions 12.0 up to and including 12.7.4.
4
What type of vulnerability is CVE-2020-7972?
CVE-2020-7972 is classified as an insecure permissions vulnerability.
5
Is CVE-2020-7972 related to data exposure risks?
Yes, CVE-2020-7972 can lead to unauthorized access and potential data exposure due to insecure permissions.