Medium severity6.5NVD Advisory· Published Mar 27, 2020· Updated Jun 17, 2026
CVE-2020-10955
CVE-2020-10955
Description
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.1.0,<12.9.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.1.0,<12.9.1
- GitLab/GitLab EE/CEdescription
- Range: 11.1 - 12.9
Patches
Vulnerability mechanics
References
3- about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/nvdRelease NotesVendor Advisory
- about.gitlab.com/releases/categories/releases/nvdRelease NotesVendor Advisory
- www.debian.org/security/2020/dsa-4691nvdThird Party Advisory
News mentions
0No linked articles in our index yet.