CVE-2020-11506: GitLab
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.
Affected products
- GitLab GitLab: from 10.7.0, before 12.7.9 (fixed in 12.7.9); from 10.7.9, before 12.7.9 (fixed in 12.7.9); from 12.8.0, before 12.8.9 (fixed in 12.8.9); from 12.9.0, before 12.9.3 (fixed in 12.9.3)
Published 2020-04-22. Last modified 2026-06-17.