CVE-2020-6832
MEDIUMCVSS 5.3/10EPSS 0.93%
Last modified
CVE-2020-6832 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 8.9.0, <= 12.6.1 |
References
- https://about.gitlab.com/blog/categories/releases/Release Notes, Vendor Advisory
- https://about.gitlab.com/releases/2020/01/13/critical-security-release-gitlab-12-dot-6-dot-4-released/Release Notes, Vendor Advisory
- https://about.gitlab.com/blog/categories/releases/Release Notes, Vendor Advisory
- https://about.gitlab.com/releases/2020/01/13/critical-security-release-gitlab-12-dot-6-dot-4-released/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6832?
An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.
How severe is CVE-2020-6832?
CVE-2020-6832 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.93% probability of exploitation in the next 30 days.
How do I fix CVE-2020-6832?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-6826Mozilla developers Tyson Smith, Bob Clary, and Alexandru Mic…9.8
- CVE-2020-6827When following a link that opened an intent://-schemed URL, …4.7
- CVE-2020-6828A malicious Android application could craft an Intent that w…7.5
- CVE-2020-6829When performing EC scalar point multiplication, the wNAF poi…5.3
- CVE-2020-6830For native-to-JS bridging, the app requires a unique token t…7.5
- CVE-2020-6831A buffer overflow could occur when parsing and validating SC…9.8
- CVE-2020-6833An issue was discovered in GitLab EE 11.3 and later. A GitLa…7.5
- CVE-2020-6835An issue was discovered in Bftpd before 5.4. There is a heap…9.8
- CVE-2020-6836grammar-parser.jison in the hot-formula-parser package befor…9.8
- CVE-2020-6838In mruby 2.1.0, there is a use-after-free in hash_values_at …9.8
- CVE-2020-6839In mruby 2.1.0, there is a stack-based buffer overflow in mr…9.8
- CVE-2020-6840In mruby 2.1.0, there is a use-after-free in hash_slice in m…9.8
Are you affected by CVE-2020-6832?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
