Launchpad.net

CVE 2020-10955

GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

See the CVE page on Mitre.org for more details.