CVE-2020-10978: GitLab

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

Affected products

  • GitLab GitLab: from 8.11.0, up to and including 12.9

Published 2020-04-08. Last modified 2026-06-17.