CVE-2020-6833 describes a GitLab Workhorse bypass vulnerability, present in GitLab EE versions 11.3 and later, which could lead to sensitive package and file disclosure through request smuggling. This high-severity flaw (CVSS 7.5) has a low attack complexity and requires no user interaction, posing a significant risk of data confidentiality compromise. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community. It is not currently listed on the KEV catalog, suggesting no widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.3.0, < 12.5.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 12.6.0, < 12.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 12.7.2, < 12.7.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.