CVE Vulnerabilities

CVE-2020-6833

Published: Feb 05, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.3.0 (including) 12.5.9 (excluding)
Gitlab Gitlab 12.6.0 (including) 12.6.6 (excluding)
Gitlab Gitlab 12.7.2 (including) 12.7.4 (excluding)

References