CVE-2020-10977

MEDIUM LAB

GitLab EE/CE <12.9 - Path Traversal

Title source: llm

Description

GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

Exploits (9)

nomisec WORKING POC 70 stars
by thewhiteh4t · poc
https://github.com/thewhiteh4t/cve-2020-10977
nomisec WORKING POC 4 stars
by KooroshRZ · poc
https://github.com/KooroshRZ/CVE-2020-10977
nomisec WORKING POC 2 stars
by vandycknick · poc
https://github.com/vandycknick/gitlab-cve-2020-10977
nomisec WORKING POC 2 stars
by liath · poc
https://github.com/liath/CVE-2020-10977
nomisec WORKING POC 1 stars
by lisp3r · poc
https://github.com/lisp3r/cve-2020-10977-read-and-execute
nomisec WORKING POC
by erk3 · poc
https://github.com/erk3/gitlab-12.9.0-file-read
nomisec WORKING POC
by possib1e · poc
https://github.com/possib1e/cve-2020-10977
nomisec WORKING POC
by JustMichi · poc
https://github.com/JustMichi/CVE-2020-10977.py
metasploit WORKING POC EXCELLENT
by William Bowling (vakzz), alanfoster · rubypocruby
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/gitlab_file_read_rce.rb

Scores

CVSS v3 5.5
EPSS 0.0477
EPSS Percentile 89.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull gitlab/gitlab-ce:12.8.1-ce.0
+6 more repos

Details

CWE
CWE-22
Status published
Products (1)
gitlab/gitlab 8.5.0 - 12.9 (2 CPE variants)
Published Apr 08, 2020
Tracked Since Feb 18, 2026