CVE-2020-10977
MEDIUM 5.5EPSS 42.7%
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
- CVSS v3.1
- 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 42.74% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2020-04-08
- Updated
- 2024-08-04
Proof-of-concept exploits (11)
- http://packetstormsecurity.com/files/160441/GitLab-File-Read-Remote-Code-Execution.html
- JustMichi/CVE-2020-10977.py0★ · 2020-11-26
- KooroshRZ/CVE-2020-109774★ · 2020-05-15
- avrah/gitlab-rce0★ · 2021-04-27
- dotPY-hax/gitlab_RCE156★ · 2020-12-16
- erk3/gitlab-12.9.0-file-read0★ · 2021-01-29
- liath/CVE-2020-109772★ · 2021-03-07
- lisp3r/cve-2020-10977-read-and-execute1★ · 2021-04-23
- possib1e/cve-2020-109770★ · 2021-01-23
- thewhiteh4t/cve-2020-1097770★ · 2021-04-23
- vandycknick/gitlab-cve-2020-109772★ · 2021-05-04