CVE-2020-10975
Description
GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
GitLab EE/CE 10.8 to 12.9 leaks metadata and comments on vulnerabilities to unauthorized users via the vulnerability feedback page.
Vulnerability
GitLab EE/CE versions 10.8 through 12.9 contain an information disclosure vulnerability in the vulnerability feedback page. The page exposes metadata and comments associated with vulnerabilities to users who should not have access, violating access control restrictions [1][2].
Exploitation
An attacker needs only network access to a vulnerable GitLab instance and can simply browse to the vulnerability feedback page. No special privileges or authentication are required beyond a valid user account on the instance; the page fails to check authorization before returning sensitive data [2].
Impact
Successful exploitation allows an unauthorized user to view metadata and comments on vulnerabilities, leading to information disclosure. This can reveal internal security discussions, vulnerability details, and potentially sensitive project information that the attacker should not have access to [1][2].
Mitigation
The vulnerability is fixed in GitLab 12.9.1, released on March 26, 2020 [2]. Users should upgrade to 12.9.1 or later. As no workarounds are available, upgrading is the recommended action. Versions 10.8 to 12.9 are affected and should be patched promptly [1][2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- GitLab/GitLab EE/CEdescription
- Range: >=10.8, <=12.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/mitrex_refsource_CONFIRM
- about.gitlab.com/releases/categories/releases/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.