VYPR
Unrated severityNVD Advisory· Published Apr 8, 2020· Updated Aug 4, 2024

CVE-2020-10978

CVE-2020-10978

Description

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

GitLab leaks issue metadata when an issue is moved from a public to a private project via the Web UI or GraphQL API, affecting versions 8.11 through 12.9.

Vulnerability

GitLab EE/CE versions 8.11 through 12.9 inadvertently leak information about issues that were created in a public project and subsequently moved to a private project. The leaked information is accessible through both the Web UI and the GraphQL API [2]. The issue affects the default configuration and does not require any special settings to be exploitable.

Exploitation

An attacker does not need any special privileges; they can be an unauthenticated user or a low-privileged user. The attacker simply views the public project's issue list or queries the GraphQL API after an issue has been moved from a public to a private project. The metadata of the moved issue (such as title, description, and comments) remains visible in the public project's historical issue data even after the move [1][2].

Impact

Successfully exploiting this vulnerability allows an attacker to gain unauthorized access to sensitive information originally intended to be private. The leaked data may include issue titles, descriptions, and discussion content, leading to information disclosure. The attacker does not gain any code execution or privilege escalation; the impact is limited to confidentiality loss [2].

Mitigation

GitLab released a fix in version 12.9.1 on March 26, 2020 [2]. Users should upgrade to GitLab 12.9.1 or later. For versions prior to 12.9.1, no workaround is documented; upgrading is the recommended mitigation. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.