HTTP Request Smuggling in GitLab Enterprise Edition - CVE-2020-11505
Published: April 23, 2020
GitLab Enterprise Edition
Detailed vulnerability description
The vulnerability allows a remote attacker to perform HTTP request smuggling attack.
The vulnerability exists due to a particular header can be used to override restriction and results in GitLab Workhorse disclosing NuGet packages and files in the "/tmp" directory. A remote attacker can send a specially crafted HTTP request to the application, perform a request smuggling attack and gain access to sensitive information on the target system.